A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.
{
"binaries": [
{
"binary_version": "2016.02.09-1ubuntu0.1~esm1",
"binary_name": "libbasicusageenvironment1"
},
{
"binary_version": "2016.02.09-1ubuntu0.1~esm1",
"binary_name": "libgroupsock8"
},
{
"binary_version": "2016.02.09-1ubuntu0.1~esm1",
"binary_name": "liblivemedia-dev"
},
{
"binary_version": "2016.02.09-1ubuntu0.1~esm1",
"binary_name": "liblivemedia50"
},
{
"binary_version": "2016.02.09-1ubuntu0.1~esm1",
"binary_name": "libusageenvironment3"
},
{
"binary_version": "2016.02.09-1ubuntu0.1~esm1",
"binary_name": "livemedia-utils"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_version": "2018.02.18-1ubuntu0.1~esm1",
"binary_name": "libbasicusageenvironment1"
},
{
"binary_version": "2018.02.18-1ubuntu0.1~esm1",
"binary_name": "libgroupsock8"
},
{
"binary_version": "2018.02.18-1ubuntu0.1~esm1",
"binary_name": "liblivemedia-dev"
},
{
"binary_version": "2018.02.18-1ubuntu0.1~esm1",
"binary_name": "liblivemedia62"
},
{
"binary_version": "2018.02.18-1ubuntu0.1~esm1",
"binary_name": "libusageenvironment3"
},
{
"binary_version": "2018.02.18-1ubuntu0.1~esm1",
"binary_name": "livemedia-utils"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}