CVE-2019-6256

A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
live555live555_media_server
0.93
debiandebian_linux
8.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
liblivemedia
lunar
dne
kinetic
dne
jammy
dne
impish
dne
hirsute
dne
groovy
Fixed 2018.11.26-1
released
focal
Fixed 2018.11.26-1
released
eoan
Fixed 2018.11.26-1
released
disco
Fixed 2018.11.26-1
released
cosmic
ignored
bionic
Fixed 2018.02.18-1ubuntu0.1~esm1
released
xenial
Fixed 2016.02.09-1ubuntu0.1~esm1
released
trusty
dne