Input validation error in LIVE555 Media Server - CVE-2019-9215

 

Input validation error in LIVE555 Media Server - CVE-2019-9215

Published: March 18, 2019


Vulnerability identifier: #VU18009
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9215
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the parseAuthorizationHeader() function. A remote attacker can perform a denial of service (DoS) attack against application using the vulnerable version of Live555 codec library.


Affected software

LIVE555 Media Server
Gentoo Linux
Opensuse
SUSE Linux
liblivemedia (Debian package)

How to mitigate CVE-2019-9215

Install updates from vendor's website.

LIVE555 Media Server - update to 2019.02.27
liblivemedia (Debian package) - update to 2016.11.28-1+deb9u2

External References

Related Security Bulletins