Use-after-free in LIVE555 Media Server - CVE-2019-7314

 

Use-after-free in LIVE555 Media Server - CVE-2019-7314

Published: February 12, 2019


Vulnerability identifier: #VU17554
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-7314
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition.

The vulnerability exists due to use-after-free error when mishandling of the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up. A remote attacker can trigger segmentation fault and cause the RTSP server to crash.


Affected software

LIVE555 Media Server
Arch Linux
Gentoo Linux
Opensuse
SUSE Linux
liblivemedia (Debian package)

How to mitigate CVE-2019-7314

Update to version 0.95.

LIVE555 Media Server - update to 0.95
liblivemedia (Debian package) - update to 2016.11.28-1+deb9u2

External References

Related Security Bulletins