A critical code execution vulnerability identified in LIVE555 Streaming Media RTSP Server library used by VLC and other media players. The vulnerability exists in the HTTP packet-parsing functionality of LIVE555 RTSP server. An attacker can send a crafted malicious packet to trigger the vulnerability and cause a stack-based buffer overflow, resulting in code execution. Cisco Talos has reported the vulnerability to Live Networks on October 10 and the vendor issued security fix on 17th October. It can be tracked as CVE-2018-4013.”]
Source: https://gbhackers.com/vulnerability-live555-streaming-media/

