Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read. An attacker can leverage this to launch a DoS attack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade live-media | Aug 22, 2024 | Aug 10, 2021 |
| Gentoo Linux | — | Upgrade media-plugins/live. | Jul 10, 2024 | Aug 10, 2021 |
| Suse | — | Upgrade libbasicusageenvironment1Upgrade libgroupsock30Upgrade libusageenvironment3Upgrade liblivemedia102 | Oct 26, 2022 | Aug 10, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub