CVE-2021-38382: Use After Free
Published Aug 10, 2021
·Updated
Live555 through 1.08 does not handle Matroska and Ogg files properly. Sending two successive RTSP SETUP commands for the same track causes a Use-After-Free and daemon crash.
Affected Software
1 affected component
Live555 live555<2021.08.06
Event History
Aug 10, 2021
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-38382.
2
What is the severity of CVE-2021-38382?
The severity of CVE-2021-38382 is medium (6.5).
3
What software is affected by CVE-2021-38382?
The Live555 version 1.08 and prior are affected by CVE-2021-38382.
4
What is the impact of CVE-2021-38382?
Exploiting CVE-2021-38382 can cause a Use-After-Free condition and crash the daemon.
5
Are there any references available for CVE-2021-38382?
Yes, you can find references for CVE-2021-38382 at the following links: - [Link 1](http://lists.live555.com/pipermail/live-devel/2021-August/021959.html) - [Link 2](http://www.live555.com/liveMedia/public/changelog.txt#[2021.08.06])