CVE Database
/

CVE-2007-6628

Back to search

CVE-2007-6628

Published: Jan 4, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port" sequence; or (2) a malformed Range header, which triggers misparsing in parse_play_time_range in RTSP_Play, as demonstrated by an empty Range header.

VendorProductVersions

n/a

n/a

affected
n/a

References

40535
vdb-entry
x_refsource_OSVDB
27049
vdb-entry
x_refsource_BID
ADV-2008-0011
vdb-entry
x_refsource_VUPEN
3507
third-party-advisory
x_refsource_SREASON
28229
third-party-advisory
x_refsource_SECUNIA
40534
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now