In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY" command, when the command specifies seeking by absolute time.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.live555.com/liveMedia/public/changelog.txt | vendor advisory |
http://lists.live555.com/pipermail/live-devel/2020-July/021662.html | mailing list exploit vendor advisory |