openSUSE-SU-2019:0058-1
Dashboard / Vulnerabilities / openSUSE-SU-2019:0058-1
openSUSE-SU-2019:0058-1
Summary: Security update for live555
Details: This update fixes two security issues in live555: - CVE-2018-4013: Remote code execution vulnerability (bsc#1114779) - CVE-2019-6256: Denial of Service issue with RTSP-over-HTTP tunneling via x-sessioncookie HTTP headers (boo#1121892) This library is statically linked into VLC. However VLC is not affected because it only uses the live555 library to implement the RTSP client.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/4NOTQMR6AICFVIHO7JSMILX3ERHDS52U/#4NOTQMR6AICFVIHO7JSMILX3ERHDS52U, https://bugzilla.suse.com/1114779, https://bugzilla.suse.com/1121892, https://www.suse.com/security/cve/CVE-2018-4013, https://www.suse.com/security/cve/CVE-2019-6256
Affected packages
Package
Name: live555
Purl: pkg:rpm/suse/live555&distro=SUSE%20Package%20Hub%2015
Affected ranges
Type: ECOSYSTEM
Events:
