The remote Debian host is missing a security-related update.
OSS-fuzz, assisted by Max Dymond, discovered that cURL, an URL transfer library, could be tricked into reading data beyond the end of a heap based buffer when parsing invalid headers in an RTSP response.
Upgrade the curl packages. For the oldstable distribution (jessie), this problem has been fixed in version 7.38.0-4+deb8u11. For the stable distribution (stretch), this problem has been fixed in version 7.52.1-5+deb9u6.