Arch Linux alert ASA-201905-17 (live-media)
| From: | Remi Gacogne <rgacogne@archlinux.org> | |
| To: | arch-security@archlinux.org | |
| Subject: | [ASA-201905-17] live-media: multiple issues | |
| Date: | Fri, 31 May 2019 17:57:08 +0200 | |
| Message-ID: | <257b8658-b2d5-7122-b4db-a99acb703f2b@archlinux.org> |
Arch Linux Security Advisory ASA-201905-17 ========================================== Severity: Critical Date : 2019-05-31 CVE-ID : CVE-2019-7314 CVE-2019-7733 Package : live-media Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-870 Summary ======= The package live-media before version 2019.05.12-1 is vulnerable to multiple issues including arbitrary code execution and denial of service. Resolution ========== Upgrade to 2019.05.12-1. # pacman -Syu "live-media>=2019.05.12-1" The problems have been fixed upstream in version 2019.05.12. Workaround ========== None. Description =========== - CVE-2019-7314 (arbitrary code execution) liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a use-after-free error that causes the RTSP server to crash (Segmentation fault) or possibly have unspecified other impact. - CVE-2019-7733 (denial of service) In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a single field (username, realm, nonce, uri, or response), only the last instance can ever be freed. Impact ====== A remote attacker can cause a crash or execute arbitrary code on the affected host via a crafted stream packet. References ========== http://lists.live555.com/pipermail/live-devel/2019-Februa... http://www.live555.com/liveMedia/public/changelog.txt https://github.com/rgaufman/live555/issues/21 https://security.archlinux.org/CVE-2019-7314 https://security.archlinux.org/CVE-2019-7733
