Multiple vulnerabilities have been discovered in LIVE555 Media Server, the worst of which could lead to a denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202407-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: LIVE555 Media Server: Multiple Vulnerabilities Date: July 09, 2024 Bugs: #732598, #807622 ID: 202407-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in LIVE555 Media Server, the worst of which could lead to a denial of service. Background ========== LIVE555 Media Server is a set of libraries for multimedia streaming. Affected packages ================= Package Vulnerable Unaffected ------------------ ------------ ------------- media-plugins/live < 2021.08.24 > = 2021.08.24 Description =========== Multiple vulnerabilities have been discovered in LIVE555 Media Server. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All LIVE555 Media Server users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-plugins/live-2021.08.24" References ========== [ 1 ] CVE-2020-24027 https://nvd.nist.gov/vuln/detail/CVE-2020-24027 [ 2 ] CVE-2021-38380 https://nvd.nist.gov/vuln/detail/CVE-2021-38380 [ 3 ] CVE-2021-38381 https://nvd.nist.gov/vuln/detail/CVE-2021-38381 [ 4 ] CVE-2021-38382 https://nvd.nist.gov/vuln/detail/CVE-2021-38382 [ 5 ] CVE-2021-39282 https://nvd.nist.gov/vuln/detail/CVE-2021-39282 [ 6 ] CVE-2021-39283 https://nvd.nist.gov/vuln/detail/CVE-2021-39283 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202407-23 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
A Denial of Service vulnerability has been reported in LIVE555 Media Server.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200803-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: LIVE555 Media Server: Denial of Service Date: March 13, 2008 Bugs: #204065 ID: 200803-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A Denial of Service vulnerability has been reported in LIVE555 Media Server. Background ========= LIVE555 Media Server is a set of libraries for multimedia streaming. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-plugins/live < 2008.02.08 > = 2008.02.08 Description ========== Luigi Auriemma reported a signedness error in the parseRTSPRequestString() function when processing short RTSP queries. Impact ===== A remote attacker could send a specially crafted RTSP query to the vulnerable server, resulting in a crash. Workaround ========= There is no known workaround at this time. Resolution ========= All LIVE555 Media Server users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-plugins/live-2008.02.08" Note: Due to ABI changes, applications built against LIVE555 Media Server such as VLC or MPlayer should also be rebuilt. References ========= [ 1 ] CVE-2007-6036 https://www.cve.org/CVERecord?id=CVE-2007-6036 Availability =========== This GLSA and any updates to it are available for viewing at theGentoo Security Website: https://security.gentoo.org/glsa/200803-22 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.