PT-2025-48491 · Unknown · Live555 Streaming Media
Heng Zhang
·
Published
2025-12-01
·
Updated
2025-12-23
·
CVE-2025-65405
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Live555 Streaming Media version 2018.09.02
Description
A use-after-free issue exists in the
ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media. This flaw allows attackers to trigger a Denial of Service (DoS) by providing a specially crafted ADTS/AAC file. Exploitation of this issue can cause a remote crash of an RTSP server.Recommendations
Update Live555 Streaming Media to a newer version that addresses this issue. As a temporary workaround, consider isolating the service to limit potential impact.
Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Live555 Streaming Media