PT-2019-1686 · Live555+2 · Liblivemedia+3

许彬彬

·

Published

2019-01-14

·

Updated

2021-03-15

·

CVE-2019-6256

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Live555 Media Server version 0.93
Description A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server. It can cause an RTSPServer crash in handleHTTPCmd TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp. The vulnerability exists due to insufficient input validation in the readSocket function of the liblivemedia library, which can allow a remote attacker to cause a denial of service.
Recommendations For Live555 Media Server version 0.93, as a temporary workaround, consider disabling the handleHTTPCmd TunnelingPOST function or restricting RTSP-over-HTTP tunneling support until a patch is available. Additionally, restrict access to the readSocket function in GroupsockHelper.cpp to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Handling of Exceptional Conditions

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01280
CVE-2019-6256
DLA-1690-1
DSA-4408-1
OPENSUSE-SU-2019:0058-1
OPENSUSE-SU-2019_0058-1
OPENSUSE-SU-2024:11023-1
USN-4853-1

Affected Products

Live555 Media Server
Suse
Ubuntu
Liblivemedia