PT-2019-6431 · Live Networks+1 · Live555+1

Zounathan

·

Published

2019-02-11

·

Updated

2020-05-15

·

CVE-2019-7733

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Live555 version 0.95
Description The issue is related to a buffer overflow caused by a large integer in a Content-Length HTTP header. This occurs because the handleRequestBytes function has an unrestricted memmove. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For Live555 version 0.95, consider restricting the use of the handleRequestBytes function until a patch is available to prevent potential buffer overflow attacks. Additionally, limiting the size of integers accepted in the Content-Length HTTP header can help mitigate the risk of exploitation.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06967
CVE-2019-7733

Affected Products

Astra Linux
Live555