ArchLinux: 201905-17: live-media: multiple issues
Summary
- CVE-2019-7314 (arbitrary code execution)
liblivemedia in Live555 before 2019.02.03 mishandles the termination of
an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could
lead to a use-after-free error that causes the RTSP server to crash
(Segmentation fault) or possibly have unspecified other impact.
- CVE-2019-7733 (denial of service)
In Live555 0.95, a setup packet can cause a memory leak leading to DoS
because, when there are multiple instances of a single field (username,
realm, nonce, uri, or response), only the last instance can ever be
freed.
Resolution
Upgrade to 2019.05.12-1.
# pacman -Syu "live-media>=2019.05.12-1"
The problems have been fixed upstream in version 2019.05.12.
References
http://lists.live555.com/pipermail/live-devel/2019-February/021143.html http://www.live555.com/liveMedia/public/changelog.txt https://github.com/rgaufman/live555/issues/21 https://security.archlinux.org/CVE-2019-7314 https://security.archlinux.org/CVE-2019-7733
Workaround
None.