Hello, 
My name is Sangjun Park, and I am a fuzzing researcher. I have identified a 
heap use-after-free (UAF) vulnerability in the live555 streaming media server 
(version 2024-09-29) running on Ubuntu 20.04. 
The issue occurs when the server processes a sequence of SETUP -> PLAY -> 
DESCRIBE requests from a client, leading to a heap UAF condition. You can 
easily reproduce the bug by following the instructions in the attached 
README.md file. 
Additionally, I have included the ASAN report and a reproduction file, which 
you can access at the following link: 
https://drive.google.com/file/d/1uq6NFkCgxOcYkkUJtnr2DzMKdoWMZ-Tp/view?usp=sharing
 
Best regards, Sangjun Park 





_______________________________________________
live-devel mailing list
live-devel@lists.live555.com
http://lists.live555.com/mailman/listinfo/live-devel

Reply via email to