The prepare_sdp_description function in ffserver.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (crash) via vectors related to the rtp format.
https://trac.ffmpeg.org/ticket/1986
http://www.ffmpeg.org/security.html
http://secunia.com/advisories/51964
http://git.videolan.org/?p=ffmpeg.git%3Ba=commitdiff%3Bh=9929991da7b843e7d80154fcacc4e80579b86a2d