VYPR

rpm package

opensuse/live555&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/live555&distro=openSUSE%20Tumbleweed

Vulnerabilities (2)

  • CVE-2026-38998MedSep 9, 2026
    affected < 2026.08.25-1.1fixed 2026.08.25-1.1

    A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server.

  • CVE-2026-41470MedMay 19, 2026
    affected < 2026.04.22-1.1fixed 2026.04.22-1.1

    LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a