CVE Vulnerabilities

CVE-2019-6256

Improper Handling of Exceptional Conditions

Published: Jan 14, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
Live555_media_serverLive5550.93 (including)0.93 (including)
LiblivemediaUbuntubionic*
LiblivemediaUbuntucosmic*
LiblivemediaUbuntudisco*
LiblivemediaUbuntueoan*
LiblivemediaUbuntuesm-apps/bionic*
LiblivemediaUbuntuesm-apps/focal*
LiblivemediaUbuntuesm-apps/xenial*
LiblivemediaUbuntufocal*
LiblivemediaUbuntugroovy*
LiblivemediaUbuntutrusty*
LiblivemediaUbuntuupstream*
LiblivemediaUbuntuxenial*

References