First published: Tue Aug 10 2021(Updated: )
Live555 through 1.08 does not handle MPEG-1 or 2 files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Live555 Live555 | <2021.08.09 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-38381.
The severity of CVE-2021-38381 is medium with a CVSS score of 6.5.
The Live555 software version up to and excluding 1.08 is affected by CVE-2021-38381.
Sending two successive RTSP SETUP commands for the same track can cause a Use-After-Free and daemon crash.
Yes, you can find more information about CVE-2021-38381 at the following links: [Link 1](http://lists.live555.com/pipermail/live-devel/2021-August/021961.html), [Link 2](http://www.live555.com/liveMedia/public/changelog.txt#[2021.08.09]).