First published: Tue Aug 10 2021(Updated: )
Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read. An attacker can leverage this to launch a DoS attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Live555 Live555 | <2021.08.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38380 is a vulnerability in Live555 through version 1.08 that mishandles huge requests for the same MP3 stream, leading to recursion and a stack-based buffer over-read.
The severity of CVE-2021-38380 is high, with a CVSS score of 7.5.
CVE-2021-38380 affects Live555 through version 1.08 by allowing an attacker to launch a DoS attack through the mishandling of huge requests for the same MP3 stream.
An attacker can leverage CVE-2021-38380 to launch a DoS attack by exploiting the recursion and stack-based buffer over-read caused by mishandling huge requests for the same MP3 stream.
Yes, a fix for CVE-2021-38380 is available in version 2021.08.04 of Live555.