Re: [Live-devel] UAF report

2022-06-18 Thread Ross Finlayson
> On Jun 18, 2022, at 3:52 AM, wengsong...@stu.scu.edu.cn wrote: > > I found that this crash only happen in a particular situation, it is so rely > on the execution sequence of handler and timeout. Please try with my webm > file again to see if it triggers crash this time As I noted before, I

Re: [Live-devel] UAF report

2022-06-18 Thread wengsongwei
I found that this crash only happen in a particular situation, it is so rely on the execution sequence of handler and timeout. Please try with my webm file again to see if it triggers crash this time, although it is no value to utilize even to dos under such restrictions. My server code should

Re: [Live-devel] UAF report

2022-06-17 Thread Ross Finlayson
Unfortunately, right now I’m not able to reproduce this crash. I changed the server (“testOnDemandRTSPServer”) to use only Session Id (22B8 in hex). And I wrote a client application that reads your “cull11” file, successively reading a 4-byte length field, then a length-field-sized da

Re: [Live-devel] UAF report

2022-06-16 Thread wengsongwei
Hello, do you have acknowledged this as a uaf bug? If yes, can I apply for a CVE ID? I saw history CVEs. Thank you. > -原始邮件- > 发件人: "Ross Finlayson" > 发送时间: 2022-06-16 19:27:21 (星期四) > 收件人: "LIVE555 Streaming Media - development & use" >

Re: [Live-devel] UAF report

2022-06-16 Thread Ross Finlayson
Many thanks for the report. We will fix this bug soon, in an upcoming release (and will report to this mailing list when a new version of the code is available.) Ross Finlayson Live Networks, Inc. http://www.live555.com/ ___ live-devel mailing list