Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:0058-1

Опубликовано: 23 мар. 2019
Источник: suse-cvrf

Описание

Security update for live555

This update fixes two security issues in live555:

  • CVE-2018-4013: Remote code execution vulnerability (bsc#1114779)
  • CVE-2019-6256: Denial of Service issue with RTSP-over-HTTP tunneling via x-sessioncookie HTTP headers (boo#1121892)

This library is statically linked into VLC. However VLC is not affected because it only uses the live555 library to implement the RTSP client.

Список пакетов

SUSE Package Hub 15
live555-devel-2018.12.14-bp150.3.3.1
openSUSE Leap 15.0
live555-devel-2018.12.14-bp150.3.3.1

Описание

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.


Затронутые продукты
SUSE Package Hub 15:live555-devel-2018.12.14-bp150.3.3.1
openSUSE Leap 15.0:live555-devel-2018.12.14-bp150.3.3.1

Ссылки

Описание

A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.


Затронутые продукты
SUSE Package Hub 15:live555-devel-2018.12.14-bp150.3.3.1
openSUSE Leap 15.0:live555-devel-2018.12.14-bp150.3.3.1

Ссылки