Thursday, March 13, 2025
HomeVulnerabilityCritical Code Execution Vulnerability Found in Libraries Used By VLC and Other...

Critical Code Execution Vulnerability Found in Libraries Used By VLC and Other Media Players

Published on

SIEM as a Service

Follow Us on Google News

A critical code execution vulnerability identified in LIVE555 Streaming Media RTSP Server library used by VLC and other media players.

The vulnerability exists in the HTTP packet-parsing functionality of LIVE555 RTSP Server library, an attacker can send a crafted malicious packet to trigger the vulnerability and cause a stack-based buffer overflow, resulting in code execution.

The LIVE555 Streaming Media contains a set of open-source C++ libraries that developed by Live Networks Inc for streaming multimedia. The libraries support for a set of streaming standards such as RTSP/RTCP/RTSP/SIP/RTP that supports both clients and server.

LIVE555 Media Libraries used by most popular media players like such as VLC and MPlayer and multitude of embedded devices such as cameras.

The vulnerability resides in the function that parses HTTP headers for tunneling RTSP over HTTP. An attacker may create a packet containing multiple “Accept:” or “x-sessioncookie” strings which could cause a stack buffer overflow in the function “lookForHeader.” reads Talos vulnerability report.

The vulnerability was found in Live Networks LIVE555 Media Server, version 0.92 and the earlier versions. It can be tracked as CVE-2018-4013.

Cisco Talos has reported the vulnerability to Live Networks on October 10 and the vendor issued security fix on 17th October.

Related Read

Tumblr Fixes Critical Security Bug That Exposes User Account Details

DOM-based XSS Vulnerability Affected 685 Million Users of Tinder, Shopify, Western Union, and Imgur

Facebook Now Revealed Hackers Stolen 29 Million Facebook Users Personal Data

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Blind Eagle Targets Organizations with Weaponized .URL Files to Steal User Hashes

In a significant development in the cybersecurity landscape, APT-C-36, more commonly known as Blind...

INE Security Alert: Using AI-Driven Cybersecurity Training to Counter Emerging Threats

As Artificial Intelligence (AI)-powered cyber threats surge, INE Security, a global leader in cybersecurity...

Apache NiFi Vulnerability Exposes MongoDB Credentials to Attackers

A critical security vulnerability has been identified in Apache NiFi, a popular open-source data...

86,000+ Healthcare Staff Records Exposed Due to AWS S3 Misconfiguration

A non-password-protected database belonging to ESHYFT, a New Jersey-based HealthTech company, was recently discovered...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Blind Eagle Targets Organizations with Weaponized .URL Files to Steal User Hashes

In a significant development in the cybersecurity landscape, APT-C-36, more commonly known as Blind...

Apache NiFi Vulnerability Exposes MongoDB Credentials to Attackers

A critical security vulnerability has been identified in Apache NiFi, a popular open-source data...

Microsoft Finally Patches 2-Year-Old Windows Kernel Security Flaw

Microsoft has released a critical patch for a 2-year-old Windows kernel security vulnerability.This...