rpm package
opensuse/live555&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/live555&distro=openSUSE%20Leap%2016.0
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-38998 | Med | 6.5 | < 2026.08.25-bp160.1.1 | 2026.08.25-bp160.1.1 | Sep 9, 2026 | A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server. | |
| CVE-2026-41470 | Med | 5.9 | < 2026.08.25-bp160.1.1 | 2026.08.25-bp160.1.1 | May 19, 2026 | LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a |
- affected < 2026.08.25-bp160.1.1fixed 2026.08.25-bp160.1.1
A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server.
- affected < 2026.08.25-bp160.1.1fixed 2026.08.25-bp160.1.1
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a