Input validation error in LIVE555 Media Server - CVE-2019-9215
Published: March 18, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the parseAuthorizationHeader() function. A remote attacker can perform a denial of service (DoS) attack against application using the vulnerable version of Live555 codec library.
Affected software
Gentoo Linux
Opensuse
SUSE Linux
liblivemedia (Debian package)
How to mitigate CVE-2019-9215
liblivemedia (Debian package) - update to 2016.11.28-1+deb9u2