PT-2019-18730 · Live Networks · Live555
Zounathan
·
Published
2019-02-11
·
Updated
2020-08-24
·
CVE-2019-7732
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Live555 version 0.95
Description
A memory leak can occur due to a setup packet, potentially leading to a denial of service (DoS) because when there are multiple instances of certain fields, such as
username, realm, nonce, uri, or response, only the last instance can be freed.Recommendations
For Live555 version 0.95, consider restricting the handling of setup packets to prevent the memory leak until a fix is available. As a temporary workaround, review the code to ensure proper memory management for multiple instances of fields like
username, realm, nonce, uri, or response.Fix
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Live555