PT-2019-6431 · Live Networks+1 · Live555+1

Zounathan

·

Publicado

2019-02-11

·

Atualizado

2020-05-15

·

CVE-2019-7733

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Live555 version 0.95
Description The issue is related to a buffer overflow caused by a large integer in a Content-Length HTTP header. This occurs because the handleRequestBytes function has an unrestricted memmove. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For Live555 version 0.95, consider restricting the use of the handleRequestBytes function until a patch is available to prevent potential buffer overflow attacks. Additionally, limiting the size of integers accepted in the Content-Length HTTP header can help mitigate the risk of exploitation.

Exploit

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-06967
CVE-2019-7733

Produtos afetados

Astra Linux
Live555