Debian Security Advisory

DLA-1720-1 liblivemedia -- LTS security update

Date Reported:
18 Mar 2019
Affected Packages:
liblivemedia
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 924655.
In Mitre's CVE dictionary: CVE-2019-9215.
More information:

It was discovered that liblivemedia, the LIVE555 RTSP server library, is vulnerable to an invalid memory access when processing the Authorization header field. Remote attackers could leverage this vulnerability to possibly trigger code execution or denial of service (OOB access and application crash) via a crafted HTTP header.

For Debian 8 Jessie, this problem has been fixed in version 2014.01.13-1+deb8u3.

We recommend that you upgrade your liblivemedia packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS