SB2017052315 - Ubuntu update for rtmpdump
Published: May 23, 2017 Updated: May 24, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) NULL pointer dereference (CVE-ID: CVE-2015-8270)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4:
The AMF3ReadString function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to cause a denial of service (invalid pointer dereference and process crash).
2) Memory corruption (CVE-ID: CVE-2015-8271)
CWE-ID: CWE-119 - Memory corruption
CVSSv4:
The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.
3) NULL pointer dereference (CVE-ID: CVE-2015-8272)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4:
RTMPDump 2.4 allows remote attackers to trigger a denial of service (NULL pointer dereference and process crash).
Remediation
Install update from vendor's website.