CVE-2013-6933 is a denial-of-service and potential arbitrary code execution vulnerability affecting Live Networks Live555 Streaming Media versions 2011.08.13 through 2013.11.25, including its use in VideoLAN VLC Media Player. The flaw arises from an integer underflow, infinite loop, and buffer overflow triggered by a space or tab character at the beginning of an RTSP message. With a CVSS score of 7.5, this vulnerability is considered highly severe, allowing unauthenticated remote attackers to cause a crash and potentially execute code with low attack complexity. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2011-08-13CPE matchmatch criteria | cpe:2.3:a:live555:streaming_media:2011-08-13:*:*:*:*:*:*:* | ||
2011-08-20CPE matchmatch criteria | cpe:2.3:a:live555:streaming_media:2011-08-20:*:*:*:*:*:*:* | ||
2011-08-22CPE matchmatch criteria | cpe:2.3:a:live555:streaming_media:2011-08-22:*:*:*:*:*:*:* | ||
2011-09-02CPE matchmatch criteria | cpe:2.3:a:live555:streaming_media:2011-09-02:*:*:*:*:*:*:* | ||
2011-09-19CPE matchmatch criteria | cpe:2.3:a:live555:streaming_media:2011-09-19:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.