7.5
CVSSv2

CVE-2019-6256

Published: 14/01/2019 Updated: 24/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A Denial of Service issue exists in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

live555 live555 media server 0.93

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #919529 CVE-2019-6256 Package: src:liblivemedia; Maintainer for src:liblivemedia is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 16 Jan 2019 22:21:02 UTC Severity: grave Tags: security, upstream Found in versi ...
Multiple security issues were discovered in liveMedia, a set of C++ libraries for multimedia streaming which could result in the execution of arbitrary code or denial of service when parsing a malformed RTSP stream For the stable distribution (stretch), these problems have been fixed in version 20161128-1+deb9u2 We recommend that you upgrade yo ...