First published: Mon Jan 11 2021(Updated: )
In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY" command, when the command specifies seeking by absolute time.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Live555 Liblivemedia | =20200625 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24027 is a potential buffer overflow bug in the server handling of a RTSP "PLAY" command in Live Networks, Inc., liblivemedia version 20200625.
CVE-2020-24027 has a severity rating of 9.8 (critical).
CVE-2020-24027 can potentially lead to a buffer overflow in the server when a RTSP "PLAY" command specifies seeking by absolute time.
To fix CVE-2020-24027, you should update to a version of Live Networks, Inc., liblivemedia that is later than 20200625.
You can find more information about CVE-2020-24027 at the following references: [1](http://lists.live555.com/pipermail/live-devel/2020-July/021662.html), [2](http://www.live555.com/liveMedia/public/changelog.txt).