SB2017052315 - Ubuntu update for rtmpdump
Published: May 23, 2017 Updated: May 24, 2017
Security Bulletin ID
SB2017052315
Severity
High
Patch available
YES
Number of vulnerabilities
3
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) NULL pointer dereference (CVE-ID: CVE-2015-8270)
The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer dereference and process crash).2) Memory corruption (CVE-ID: CVE-2015-8271)
The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.3) NULL pointer dereference (CVE-ID: CVE-2015-8272)
RTMPDump 2.4 allows remote attackers to trigger a denial of service (NULL pointer dereference and process crash).Remediation
Install update from vendor's website.