CVE-2019-15232 PUBLISHED

Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska file demultiplexors.

EPSS 0.71% · 72.1th percentile

Risk Scores

EPSS Score
0.71%
72.1th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSliblivemedia0, 2020.01.19-1build1, 2020.01.19-1
Ubuntu:Pro:18.04:LTSliblivemedia2017.10.28-2, 0, 2017.07.18-1
Ubuntu:Pro:16.04:LTSliblivemedia2014.01.13-1, 2016.02.09-1ubuntu0.1~esm1, 0

Timeline

References

Open in Interactive Console →