#VU27926 Use-after-free in LIVE555 Streaming Media - CVE-2019-15232
Published: May 15, 2020
LIVE555 Streaming Media
Live Networks
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in GenericMediaServer::createNewClientSessionWithId() when generating client session identifiers, which is mishandled by the MPEG1or2 and Matroska file demultiplexors. A remote attacker can execute arbitrary code on the target system.