CVE-2021-38380

Name
CVE-2021-38380
Description
Live555 through 1.08 mishandles huge requests for the same MP3 stream, leading to recursion and s stack-based buffer over-read. An attacker can leverage this to launch a DoS attack.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC http://lists.live555.com/pipermail/live-devel/2021-August/021954.html
MISC http://www.live555.com/liveMedia/public/changelog.txt#[2021.08.04]

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:live555:live555:*:*:*:*:*:*:*:* live555 >= None <= 1.08
cpe:2.3:a:live555:live555:*:*:*:*:*:*:*:* live555 >= None < 2021.08.04

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
live-media edge-community 2022.02.07-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
live-media 3.22-community 2022.02.07-r0 None fixed
live-media 3.21-community 2022.02.07-r0 None fixed
live-media 3.20-community 2022.02.07-r0 None fixed
live-media 3.19-community 2022.02.07-r0 None fixed
live-media 3.18-community 2022.02.07-r0 None fixed
live-media 3.17-community 2022.02.07-r0 None fixed