CVE-2021-38381: Use After Free
Published Aug 10, 2021
·Updated
Live555 through 1.08 does not handle MPEG-1 or 2 files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.
Affected Software
1 affected component
Live555 live555<2021.08.09
Event History
Aug 10, 2021
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-38381.
2
What is the severity of CVE-2021-38381?
The severity of CVE-2021-38381 is medium with a CVSS score of 6.5.
3
What software is affected by CVE-2021-38381?
The Live555 software version up to and excluding 1.08 is affected by CVE-2021-38381.
4
What is the impact of CVE-2021-38381?
Sending two successive RTSP SETUP commands for the same track can cause a Use-After-Free and daemon crash.
5
Are there any reference links for CVE-2021-38381?
Yes, you can find more information about CVE-2021-38381 at the following links: [Link 1](http://lists.live555.com/pipermail/live-devel/2021-August/021961.html), [Link 2](http://www.live555.com/liveMedia/public/changelog.txt#[2021.08.09]).