CVE-2019-6256
published 2019-01-14CVE-2019-6256: A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in…
PriorityP344critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.41%
82.5th percentile
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| live555 | live555_media_server | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j293-2f59-6wr3: A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0
ghsa_unreviewed·2022-05-13
CVE-2019-6256 [CRITICAL] CWE-755 GHSA-j293-2f59-6wr3: A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.
OSV
liblivemedia vulnerabilities
osv·2021-03-15·CVSS 9.8
CVE-2018-4013 [CRITICAL] liblivemedia vulnerabilities
liblivemedia vulnerabilities
It was discovered that liveMedia incorrectly handled certain network
packets. An attacker could possibly use this issue to execute arbitrary
code. (CVE-2018-4013)
It was discovered that liveMedia incorrectly handled certain network
sessions. An attacker could possibly use this issue to cause a denial of
service. (CVE-2019-6256)
It was discovered that liveMedia incorrectly handled certain RTSP
streamings. An attacker could possiby use this issue to cause a denial of
service or other unspecified impact. (CVE-2019-7314)
It was discovered that liveMedia incorrectly handled certain requests. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2019-9215)
OSV
CVE-2019-6256: A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0
osv·2019-01-14·CVSS 9.8
CVE-2019-6256 [CRITICAL] CVE-2019-6256: A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.
Ubuntu
liveMedia vulnerabilities
vendor_ubuntu·2021-03-15·CVSS 9.8
CVE-2018-4013 [CRITICAL] liveMedia vulnerabilities
Title: liveMedia vulnerabilities
Summary: Several security issues were fixed in liveMedia.
It was discovered that liveMedia incorrectly handled certain network
packets. An attacker could possibly use this issue to execute arbitrary
code. (CVE-2018-4013)
It was discovered that liveMedia incorrectly handled certain network
sessions. An attacker could possibly use this issue to cause a denial of
service. (CVE-2019-6256)
It was discovered that liveMedia incorrectly handled certain RTSP
streamings. An attacker could possiby use this issue to cause a denial of
service or other unspecified impact. (CVE-2019-7314)
It was discovered that liveMedia incorrectly handled certain requests. An
attacker could possibly use this issue to obtain sensitive information.
(CVE-2019-9215)
Instructions: In g
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/rgaufman/live555/issues/19https://lists.debian.org/debian-lts-announce/2019/02/msg00037.htmlhttps://seclists.org/bugtraq/2019/Mar/22https://security.gentoo.org/glsa/202005-06https://www.debian.org/security/2019/dsa-4408https://github.com/rgaufman/live555/issues/19https://lists.debian.org/debian-lts-announce/2019/02/msg00037.htmlhttps://seclists.org/bugtraq/2019/Mar/22https://security.gentoo.org/glsa/202005-06https://www.debian.org/security/2019/dsa-4408
2019-01-14
Published