The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.
Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.
Link | Tags |
---|---|
http://www.talosintelligence.com/reports/TALOS-2016-0067/ | exploit vdb entry third party advisory technical description |
http://www.securityfocus.com/bid/95125 | vdb entry third party advisory |
http://www.debian.org/security/2017/dsa-3850 | vendor advisory |