PT-2025-48491 · Unknown · Live555 Streaming Media

Heng Zhang

·

Published

2025-12-01

·

Updated

2025-12-23

·

CVE-2025-65405

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Live555 Streaming Media version 2018.09.02
Description A use-after-free issue exists in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media. This flaw allows attackers to trigger a Denial of Service (DoS) by providing a specially crafted ADTS/AAC file. Exploitation of this issue can cause a remote crash of an RTSP server.
Recommendations Update Live555 Streaming Media to a newer version that addresses this issue. As a temporary workaround, consider isolating the service to limit potential impact.

Exploit

Fix

DoS

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2025-65405

Affected Products

Live555 Streaming Media