Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Ubuntu 12.04 ESM: USN-3283-2 Critical: rtmpdump Denial of Service

Ubuntu Large Esm H500
rtmpdump could be made to crash or run programs as your login if it processed a specially crafted stream.
=========================================================================Ubuntu Security Notice USN-3283-2
May 23, 2017

rtmpdump vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

rtmpdump could be made to crash or run programs as your login if it processed
a specially crafted stream.

Software Description:
- rtmpdump: small dumper for media content streamed over the RTMP protocol

Details:

Dave McDaniel discovered that rtmpdump incorrectly handled certain
malformed streams. If a user were tricked into processing a specially
crafted stream, a remote attacker could cause rtmpdump to crash, resulting
in a denial of service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  librtmp0                        2.4~20110711.gitc28f1bab-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-3283-2
  https://ubuntu.com/security/notices/USN-3283-1
  CVE-2015-8270, CVE-2015-8271, CVE-2015-8272

Ubuntu 12.04 ESM: USN-3283-2 Critical: rtmpdump Denial of Service

ubuntu
Calendar Grey May 23, 2017
Dist Ubuntu Esm H88
Ensure your Ubuntu installation is up to date to resolve security issues associated with rtmpdump. This will help avert system crashes and the risk of remote code exploitation.
rtmpdump could be made to crash or run programs as your login if it processed a specially crafted stream.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM:   librtmp0                        2.4~20110711.gitc28f1bab-1ubuntu0.1 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3283-2

  https://ubuntu.com/security/notices/USN-3283-1

  CVE-2015-8270, CVE-2015-8271, CVE-2015-8272

Severity
critical
Lowest
Low
Medium
High
Critical

May 23, 2017

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here