A code execution vulnerability has been discovered in Live Networks’ LIVE555 streaming media library. The vulnerability resides in the HTTP packet-parsing function of the LIVE555 RTSP, which parses HTTP headers for tunneling RTSP over HTTP. The library is being used by well-known media software such as VLC and MPlayer, security researchers say. Vulnerability is tracked as CVE-2018-4013 and discovered by researcher Lilith Wyatt of Cisco Talos Intelligence Group. Vulnerabilities were reported to Live Networks on October 10 and publicly disclosed on October 18.
Source: https://thehackernews.com/2018/10/critical-flaw-found-in-streaming.html

