Vulnerability Description
Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska file demultiplexors.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Live555 | Streaming Media | < 2019-08-16 |
Related Weaknesses (CWE)
References
- http://www.live555.com/liveMedia/public/changelog.txtRelease NotesVendor Advisory
- https://security.gentoo.org/glsa/202005-06Third Party Advisory
- http://www.live555.com/liveMedia/public/changelog.txtRelease NotesVendor Advisory
- https://security.gentoo.org/glsa/202005-06Third Party Advisory
FAQ
What is CVE-2019-15232?
CVE-2019-15232 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and M...
How severe is CVE-2019-15232?
CVE-2019-15232 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-15232?
Check the references section above for vendor advisories and patch information. Affected products include: Live555 Streaming Media.