Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska file demultiplexors.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade media-plugins/live. | Jun 15, 2020 | Aug 20, 2019 |
| Suse | — | Upgrade live555-develUpgrade libgroupsock30Upgrade libbasicusageenvironment1Upgrade live555Upgrade libusageenvironment3Upgrade liblivemedia94 | Jun 25, 2021 | Aug 20, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Aug 20, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub