Hello, 
My name is Sangjun Park, and I am a fuzzing researcher. I have discovered a 
heap use-after-free (UAF) vulnerability in the live555 streaming media server 
(version 2024-09-29) running on Ubuntu 20.04. 
The issue arises when the server handles a sequence of SETUP and other related 
client requests, leading to a heap UAF condition. You can easily reproduce the 
bug by following the steps provided in the attached README.md. 
Additionally, I have attached the ASAN report and a reproducible test case, 
which you can access via the following link: 
https://drive.google.com/file/d/16KZK8IVF8ax2s5elZHXbMkVjLcGXnRxJ/view?usp=sharing
 
Best regards, Sangjun Park



_______________________________________________
live-devel mailing list
live-devel@lists.live555.com
http://lists.live555.com/mailman/listinfo/live-devel

Reply via email to