Vulnerability Name:

CVE-2013-6933 (CCN-90734)

Assigned:2013-12-30
Published:2013-12-30
Updated:2019-09-12
Summary:The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-189
CWE-119
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2013-6933

Source: CCN
Type: iSEC Partners Web site
Fuzzing RTSP to discover an exploitable vulnerability in VLC

Source: MISC
Type: UNKNOWN
http://isecpartners.github.io/fuzzing/vulnerabilities/2013/12/30/vlc-vulnerability.html

Source: CCN
Type: LIVE555 Web site
LIVE555 Streaming Media

Source: CONFIRM
Type: UNKNOWN
http://www.live555.com/liveMedia/public/changelog.txt

Source: CCN
Type: BID-65131
LIVE555 Streaming Media 'parseRTSPRequestString()' Function Buffer Overflow Vulnerability

Source: XF
Type: UNKNOWN
live555-parsertsprequeststring-bo(90734)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:live555:streaming_media:2011-08-13:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-08-20:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-08-22:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-09-02:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-09-19:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-10-05:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-10-09:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-10-18:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-10-27:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-11-02:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-11-08:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-11-20:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-11-27:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-11-28:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-11-29:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-12-02:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-12-19:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-12-20:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2011-12-23:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-01-07:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-01-13:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-01-25:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-01-26:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-02-03:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-02-04:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-02-29:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-03-20:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-03-22:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-04-04:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-04-18:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-04-21:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-04-26:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-04-27:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-05-03:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-05-11:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-05-17:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-06-12:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-06-17:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-06-23:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-06-26:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-07-03:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-07-06:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-07-14:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-07-18:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-07-24:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-07-26:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-08-08:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-08-12:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-08-17:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-08-20:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-08-28:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-08-29:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-08-30:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-08-31:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-09-06:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-09-07:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-09-11:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-09-12:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-09-13:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-09-27:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-10-01:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-10-04:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-10-11:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-10-12:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-10-16:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-10-17:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-10-18:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-10-21:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-10-22:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-10-24:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-11-05:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-11-08:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-11-16:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-11-17:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-11-22:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-11-28:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-11-29:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-11-30:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-12-15:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-12-18:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-12-21:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-12-22:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-12-23:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2012-12-24:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-01-03:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-01-04:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-01-05:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-01-15:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-01-18:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-01-19:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-01-21:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-01-22:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-01-23:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-01-25:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-02-05:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-02-11:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-02-27:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-03-07:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-03-23:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-03-31:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-01:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-04:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-05:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-06:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-08:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-16:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-21:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-22:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-23:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-29:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-04-30:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-05-30:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-06-06:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-06-14:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-06-18:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-06-30:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-07-03:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-07-16:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-07-30:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-07-31:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-08-05:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-08-15:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-08-16:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-08-28:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-08-31:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-09-07:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-09-08:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-09-11:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-09-18:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-09-27:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-09-30:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-01:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-02:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-03:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-07:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-08:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-09:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-11:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-16:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-18:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-22:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-24:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-10-25:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-11-06:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-11-10:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-11-14:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-11-15:*:*:*:*:*:*:*
  • OR cpe:/a:live555:streaming_media:2013-11-25:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:26500
    V
    Denial of service and possibly execute arbitrary code via a space or tab character at the beginning of an RTSP message
    2014-10-20
    oval:com.ubuntu.xenial:def:201369330000000
    V
    CVE-2013-6933 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-01-23
    oval:com.ubuntu.artful:def:20136933000
    V
    CVE-2013-6933 on Ubuntu 17.10 (artful) - medium.
    2014-01-23
    oval:com.ubuntu.xenial:def:20136933000
    V
    CVE-2013-6933 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-01-23
    oval:com.ubuntu.bionic:def:20136933000
    V
    CVE-2013-6933 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-01-23
    oval:com.ubuntu.precise:def:20136933000
    V
    CVE-2013-6933 on Ubuntu 12.04 LTS (precise) - medium.
    2014-01-23
    oval:com.ubuntu.bionic:def:201369330000000
    V
    CVE-2013-6933 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-01-23
    oval:com.ubuntu.trusty:def:20136933000
    V
    CVE-2013-6933 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-01-23
    BACK
    live555 streaming media 2011-08-13
    live555 streaming media 2011-08-20
    live555 streaming media 2011-08-22
    live555 streaming media 2011-09-02
    live555 streaming media 2011-09-19
    live555 streaming media 2011-10-05
    live555 streaming media 2011-10-09
    live555 streaming media 2011-10-18
    live555 streaming media 2011-10-27
    live555 streaming media 2011-11-02
    live555 streaming media 2011-11-08
    live555 streaming media 2011-11-20
    live555 streaming media 2011-11-27
    live555 streaming media 2011-11-28
    live555 streaming media 2011-11-29
    live555 streaming media 2011-12-02
    live555 streaming media 2011-12-19
    live555 streaming media 2011-12-20
    live555 streaming media 2011-12-23
    live555 streaming media 2012-01-07
    live555 streaming media 2012-01-13
    live555 streaming media 2012-01-25
    live555 streaming media 2012-01-26
    live555 streaming media 2012-02-03
    live555 streaming media 2012-02-04
    live555 streaming media 2012-02-29
    live555 streaming media 2012-03-20
    live555 streaming media 2012-03-22
    live555 streaming media 2012-04-04
    live555 streaming media 2012-04-18
    live555 streaming media 2012-04-21
    live555 streaming media 2012-04-26
    live555 streaming media 2012-04-27
    live555 streaming media 2012-05-03
    live555 streaming media 2012-05-11
    live555 streaming media 2012-05-17
    live555 streaming media 2012-06-12
    live555 streaming media 2012-06-17
    live555 streaming media 2012-06-23
    live555 streaming media 2012-06-26
    live555 streaming media 2012-07-03
    live555 streaming media 2012-07-06
    live555 streaming media 2012-07-14
    live555 streaming media 2012-07-18
    live555 streaming media 2012-07-24
    live555 streaming media 2012-07-26
    live555 streaming media 2012-08-08
    live555 streaming media 2012-08-12
    live555 streaming media 2012-08-17
    live555 streaming media 2012-08-20
    live555 streaming media 2012-08-28
    live555 streaming media 2012-08-29
    live555 streaming media 2012-08-30
    live555 streaming media 2012-08-31
    live555 streaming media 2012-09-06
    live555 streaming media 2012-09-07
    live555 streaming media 2012-09-11
    live555 streaming media 2012-09-12
    live555 streaming media 2012-09-13
    live555 streaming media 2012-09-27
    live555 streaming media 2012-10-01
    live555 streaming media 2012-10-04
    live555 streaming media 2012-10-11
    live555 streaming media 2012-10-12
    live555 streaming media 2012-10-16
    live555 streaming media 2012-10-17
    live555 streaming media 2012-10-18
    live555 streaming media 2012-10-21
    live555 streaming media 2012-10-22
    live555 streaming media 2012-10-24
    live555 streaming media 2012-11-05
    live555 streaming media 2012-11-08
    live555 streaming media 2012-11-16
    live555 streaming media 2012-11-17
    live555 streaming media 2012-11-22
    live555 streaming media 2012-11-28
    live555 streaming media 2012-11-29
    live555 streaming media 2012-11-30
    live555 streaming media 2012-12-15
    live555 streaming media 2012-12-18
    live555 streaming media 2012-12-21
    live555 streaming media 2012-12-22
    live555 streaming media 2012-12-23
    live555 streaming media 2012-12-24
    live555 streaming media 2013-01-03
    live555 streaming media 2013-01-04
    live555 streaming media 2013-01-05
    live555 streaming media 2013-01-15
    live555 streaming media 2013-01-18
    live555 streaming media 2013-01-19
    live555 streaming media 2013-01-21
    live555 streaming media 2013-01-22
    live555 streaming media 2013-01-23
    live555 streaming media 2013-01-25
    live555 streaming media 2013-02-05
    live555 streaming media 2013-02-11
    live555 streaming media 2013-02-27
    live555 streaming media 2013-03-07
    live555 streaming media 2013-03-23
    live555 streaming media 2013-03-31
    live555 streaming media 2013-04-01
    live555 streaming media 2013-04-04
    live555 streaming media 2013-04-05
    live555 streaming media 2013-04-06
    live555 streaming media 2013-04-08
    live555 streaming media 2013-04-16
    live555 streaming media 2013-04-21
    live555 streaming media 2013-04-22
    live555 streaming media 2013-04-23
    live555 streaming media 2013-04-29
    live555 streaming media 2013-04-30
    live555 streaming media 2013-05-30
    live555 streaming media 2013-06-06
    live555 streaming media 2013-06-14
    live555 streaming media 2013-06-18
    live555 streaming media 2013-06-30
    live555 streaming media 2013-07-03
    live555 streaming media 2013-07-16
    live555 streaming media 2013-07-30
    live555 streaming media 2013-07-31
    live555 streaming media 2013-08-05
    live555 streaming media 2013-08-15
    live555 streaming media 2013-08-16
    live555 streaming media 2013-08-28
    live555 streaming media 2013-08-31
    live555 streaming media 2013-09-07
    live555 streaming media 2013-09-08
    live555 streaming media 2013-09-11
    live555 streaming media 2013-09-18
    live555 streaming media 2013-09-27
    live555 streaming media 2013-09-30
    live555 streaming media 2013-10-01
    live555 streaming media 2013-10-02
    live555 streaming media 2013-10-03
    live555 streaming media 2013-10-07
    live555 streaming media 2013-10-08
    live555 streaming media 2013-10-09
    live555 streaming media 2013-10-11
    live555 streaming media 2013-10-16
    live555 streaming media 2013-10-18
    live555 streaming media 2013-10-22
    live555 streaming media 2013-10-24
    live555 streaming media 2013-10-25
    live555 streaming media 2013-11-06
    live555 streaming media 2013-11-10
    live555 streaming media 2013-11-14
    live555 streaming media 2013-11-15
    live555 streaming media 2013-11-25