A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage https://nvd.nist.gov/vuln/detail/CVE-2018-1000122