PT-2019-1686 · Live555+2 · Liblivemedia+3
许彬彬
·
Published
2019-01-14
·
Updated
2021-03-15
·
CVE-2019-6256
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Live555 Media Server version 0.93
Description
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server. It can cause an RTSPServer crash in
handleHTTPCmd TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp. The vulnerability exists due to insufficient input validation in the readSocket function of the liblivemedia library, which can allow a remote attacker to cause a denial of service.Recommendations
For Live555 Media Server version 0.93, as a temporary workaround, consider disabling the
handleHTTPCmd TunnelingPOST function or restricting RTSP-over-HTTP tunneling support until a patch is available. Additionally, restrict access to the readSocket function in GroupsockHelper.cpp to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Improper Handling of Exceptional Conditions
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Live555 Media Server
Suse
Ubuntu
Liblivemedia