CVE-2019-6256
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.41% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-755
- Affected
- live555/live555 media server · debian/debian linux
- Source
- cve@mitre.org
References
- https://github.com/rgaufman/live555/issues/19Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/02/msg00037.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Mar/22Issue Tracking, Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202005-06
- https://www.debian.org/security/2019/dsa-4408Third Party Advisory
- https://github.com/rgaufman/live555/issues/19Exploit, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/02/msg00037.htmlMailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Mar/22Issue Tracking, Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202005-06
- https://www.debian.org/security/2019/dsa-4408Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.