CVE-2019-15232

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
20/08/2019
Last modified:
29/03/2023

Description

Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska file demultiplexors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:live555:streaming_media:*:*:*:*:*:*:*:* 2019-08-16 (excluding)