Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-60458

Опубликовано: 29 дек. 2025
Источник: debian
EPSS Низкий

Описание

UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
uxplayfixed1.72.3-1package
uxplayno-dsatrixiepackage
uxplayno-dsabookwormpackage

Примечания

  • https://github.com/0pepsi/CVE-2025-60458

  • https://github.com/FDH2/UxPlay/issues/486

  • https://github.com/FDH2/UxPlay/issues/441

  • Fixed by: https://github.com/FDH2/UxPlay/commit/747d9ffadfc126c6951eca7eae7063e50a7c3f78 (v1.72.3)

EPSS

Процентиль: 16%
0.00049
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.

CVSS3: 6.5
nvd
около 1 месяца назад

UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.

CVSS3: 6.5
github
около 1 месяца назад

UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.

EPSS

Процентиль: 16%
0.00049
Низкий