Cijliu Librtsp Buffer Overflow Vulnerability in Rtsp_Parse_Method
Vulnerability
A buffer overflow vulnerability has been identified in Cijliu Librtsp versions up to commit 2ec1a81ad65280568a0c7c16420d7c10fde13b04. The issue arises in the rtsp_parse_method function, where improper input handling can be exploited to manipulate memory. This vulnerability requires local access to exploit.
Impact
Exploitation of this vulnerability leads to a buffer overflow, which can commonly result in arbitrary code execution or causing a program to crash.
Reproduction
The vulnerability can be reproduced by building the Librtsp library and running the example demo application. The server should be started with Valgrind to monitor for memory errors. Then, a crafted RTSP request can be sent to the server on port 8554, which will trigger the buffer overflow.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
