PT-2020-10164 · Wowza · Wowza Streaming Engine

Published

2020-08-03

·

Updated

2022-04-28

·

CVE-2019-19455

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wowza Streaming Engine versions prior to 4.8.5
Description The issue concerns insecure permissions in the Linux version of the server, potentially allowing a local attacker to escalate privileges by writing arbitrary commands in any file and executing them as root. This was resolved in version 4.8.5.
Recommendations For versions prior to 4.8.5, update to version 4.8.5 to resolve the issue. As a temporary workaround, consider restricting access to the /usr/local/WowzaStreamingEngine/manager/bin/ directory to prevent arbitrary command execution.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19455

Affected Products

Wowza Streaming Engine