UBUNTU-CVE-2019-15232
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-15232
Summary:
Details: Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska file demultiplexors.
References: https://ubuntu.com/security/CVE-2019-15232, http://www.live555.com/liveMedia/public/changelog.txt, https://www.cve.org/CVERecord?id=CVE-2019-15232
Affected packages
Package
Name: liblivemedia
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
2014.01.13-1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
