CVE-2013-6933

EUVD-2013-6734
The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Debian logo
Debian Releases
Debian Product
Codename
mplayer
bookworm
2:1.5+svn38408-1
fixed
bullseye
2:1.4+ds1-1+deb11u1
fixed
sid
2:1.5+svn38542-1
fixed
squeeze
no-dsa
vlc
bookworm
3.0.21-0+deb12u1
fixed
bookworm (security)
3.0.21-0+deb12u1
fixed
bullseye
3.0.21-0+deb11u1
fixed
bullseye (security)
3.0.21-0+deb11u1
fixed
sid
3.0.21-2
fixed
squeeze
no-dsa
trixie
3.0.21-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
liblivemedia
artful
ignored
bionic
not-affected
lucid
ignored
precise
ignored
quantal
ignored
raring
ignored
saucy
ignored
trusty
dne
utopic
ignored
vivid
ignored
wily
ignored
xenial
not-affected
yakkety
ignored
zesty
ignored