PT-2020-10164 · Wowza · Wowza Streaming Engine
Published
2020-08-03
·
Updated
2022-04-28
·
CVE-2019-19455
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wowza Streaming Engine versions prior to 4.8.5
Description
The issue concerns insecure permissions in the Linux version of the server, potentially allowing a local attacker to escalate privileges by writing arbitrary commands in any file and executing them as root. This was resolved in version 4.8.5.
Recommendations
For versions prior to 4.8.5, update to version 4.8.5 to resolve the issue. As a temporary workaround, consider restricting access to the
/usr/local/WowzaStreamingEngine/manager/bin/ directory to prevent arbitrary command execution.Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wowza Streaming Engine