openSUSE-SU-2020:0944-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0944-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2020:0944-1
Upstream
Related
Published
2020-07-06T22:29:21Z
Modified
2026-03-11T07:32:33.815205Z
Summary
Security update for live555
Details

This update for live555 fixes the following issues:

  • CVE-2019-9215: Malformed headers could have lead to invalid memory access in the parseAuthorizationHeader function. (boo#1127341)

  • CVE-2019-7314: Mishandled termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up could have lead to a Use-After-Free error causing the RTSP server to crash or possibly have unspecified other impact. (boo#1124159)

  • Update to version 2019.06.28,

  • Convert to dynamic libraries (boo#1121995):
    • Use make ilinux-with-shared-libraries: build the dynamic libs instead of the static one.
    • Use make install instead of a manual file copy script: this also reveals that we missed quite a bit of code to be installed before.
    • Split out shared library packages according the SLPP.
  • Use FAT LTO objects in order to provide proper static library.

This update was imported from the openSUSE:Leap:15.1:Update update project.

References

Affected packages

openSUSE:Leap 15.2 / live555

Package

Name
live555
Purl
pkg:rpm/opensuse/live555&distro=openSUSE%20Leap%2015.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2019.06.28-lp152.3.3.1

Ecosystem specific

{
    "binaries": [
        {
            "live555": "2019.06.28-lp152.3.3.1",
            "libliveMedia66": "2019.06.28-lp152.3.3.1",
            "libUsageEnvironment3": "2019.06.28-lp152.3.3.1",
            "libgroupsock8": "2019.06.28-lp152.3.3.1",
            "libBasicUsageEnvironment1": "2019.06.28-lp152.3.3.1",
            "live555-devel": "2019.06.28-lp152.3.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0944-1.json"