7.5
CVSSv3

CVE-2019-7733

Published: 11/02/2019 Updated: 15/05/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestBytes has an unrestricted memmove.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

live555 streaming media 0.95

Vendor Advisories

Debian Bug report logs - #929948 CVE-2019-7733 Package: src:liblivemedia; Maintainer for src:liblivemedia is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 3 Jun 2019 20:30:01 UTC Severity: important Tags: fixed-upstream, security, upst ...
In Live555 095, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance can ever be freed ...