MGASA-2021-0313
Dashboard / Vulnerabilities / MGASA-2021-0313
MGASA-2021-0313
Summary: Updated live packages fix security vulnerabilities
Details: Updated live packages fix security vulnerabilities: Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska file demultiplexors (CVE-2019-15232). Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsessionLive OnDemandServerMediaSubsession subclasses in Networks LIVE555 Streaming Media before 2021.3.16 (CVE-2021-28899). The mplayer package has been rebuilt against the updated live package.
References: https://advisories.mageia.org/MGASA-2021-0313.html, https://bugs.mageia.org/show_bug.cgi?id=29175, http://lists.live555.com/pipermail/live-devel/2021-March/021891.html, http://live555.com/liveMedia/public/changelog.txt, https://lists.opensuse.org/archives/list/[email protected]/thread/Y7ZOGH7UAC6Q7OJHR62KOMWS64YF4G73/
Affected packages
Package
Name: live
Purl: pkg:rpm/mageia/live?arch=source&distro=mageia-7
Affected ranges
Type: ECOSYSTEM
Events:
