7.5
CVSSv2

CVE-2006-2022

Published: 25/04/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and previous versions allows remote malicious users to execute arbitrary code via a long URL.

Vulnerable Product Search on Vulmon Subscribe to Product

ls3 fenice

Exploits

/* IHS Iran Homeland Security public source code Fenice - Open Media Streaming Server remote BOF exploit author : c0d3r "kaveh razavi" c0d3r@ihsteamcom package : fenice-110targz and prolly prior versions workaround : update after patch release advisory : wwwsecurityfocuscom/bid/17678 company address : streamingpolitoit/ ...
/* ** ** Fedora Core 6 (exec-shield) based ** Fenice OMS server (fenice-110targz) remote root exploit ** by Xpl017Elz ** ** Advanced exploitation in exec-shield (Fedora Core case study) ** URL: x82inetcoporg/h0me/papers/FC_exploit/FC_exploittxt ** ** Reference: wwwsecurityfocuscom/bid/17678 ** vendor: streamingpolitoi ...