Bug#964552: [Security Issue][liblivemedia] stack buffer overflow in liblivemedia

2020-07-08 Thread Sebastian Ramacher
Control: tags -1 + moreinfo Hi On 2020-07-08 23:21:30 +0800, Xiaobo Xiang wrote: > Package: liblivemedia > Version: 06.25 > > [summary] > In the latest version of live555 mediaserver, there is a stack based buffer > overflow vulnerability when parsing 'PLAY' command. Which version do you mean?

Bug#964552: [Security Issue][liblivemedia] stack buffer overflow in liblivemedia

2020-07-08 Thread Xiaobo Xiang
Package: liblivemedia Version: 06.25 [summary] In the latest version of live555 mediaserver, there is a stack based buffer overflow vulnerability when parsing 'PLAY' command. An attacker is able to send a sequence of malformed RTSP packets to trigger this issue. In the worst case, the media serve