PT-2021-22095 · Live555+1 · Live555+1

Published

2021-08-08

·

Updated

2021-08-20

·

CVE-2021-38381

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Live555 versions 1.08 and earlier
Description The issue arises from improper handling of MPEG-1 or 2 files. Specifically, sending two successive RTSP SETUP commands for the same track can cause a Use-After-Free condition, leading to a daemon crash.
Recommendations For versions 1.08 and earlier, consider disabling the RTSP SETUP command for the same track to prevent the Use-After-Free condition until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03984
CVE-2021-38381
OPENSUSE-SU-2024:11023-1

Affected Products

Astra Linux
Live555