Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a short time invokes the error-handling module, in which a heap-based buffer overflow happens. An attacker can leverage this to launch a DoS attack.
References
Link Resource
http://lists.live555.com/pipermail/live-devel/2021-September/021994.html Exploit Mailing List Vendor Advisory
http://www.live555.com/liveMedia/public/changelog.txt Release Notes Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-07-11T11:38:05

Updated: 2022-07-11T11:38:04

Reserved: 2021-09-20T00:00:00


Link: CVE-2021-41396

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-07-12T14:15:14.797

Modified: 2022-07-18T18:59:17.500


Link: CVE-2021-41396

JSON object: View

cve-icon Redhat Information

No data.

CWE