Real Time Streaming Protocol RTSP is a protocol for use in streaming media systems which allows a client to remotely control a streaming media server, issuing VCR-like commands such as "play" and "pause", and allowing time-based access to files on a server.
The vulnerability is caused due to an bound checking error while processing RTSP Replies. The vulnerability could be exploited via a specially crafted RTSP reply containing an overly long Content-Type header.
An attacker could exploit this vulnerability by creating specially crafted web page and persuading user to visit webpage or by persuading user into opening a specially crafted QTL file. Successful exploitation allows the attacker to execute arbitrary code to take complete control of the system.
It may be noted that exploit Code for the vulnerability is available in the wild.
The information provided herein is on "as is" basis, without warranty of any kind.