[Live-devel] UAF in Live555

Ba Jinsheng bajinsheng at u.nus.edu
Sun Aug 8 21:47:33 PDT 2021

Dear Ross Finlayson,

Thanks for your reply!

I find another similar UAF issue in the "mpg" file streaming:

[cid:image001.png at 01D78D1C.7BCA3890]

I attach the poc in attachment.

Best regards,

Jinsheng Ba

-----Original Message-----
From: live-devel <live-devel-bounces at us.live555.com> On Behalf Of Ross Finlayson
Sent: Saturday, August 7, 2021 6:54 AM
To: LIVE555 Streaming Media - development & use <live-devel at us.live555.com>
Subject: Re: [Live-devel] UAF in Live555

        - External Email -


Thanks for the report.  I have just installed a new version (2021.08.06) that fixes this bug.

If you have a LIVE555-based RTSP server that can serve “.mkv”, “.webm”, or “.ogg” files, then you should upgrade to this new version ASAP.

Ross Finlayson

Live Networks, Inc.



live-devel mailing list

live-devel at lists.live555.com<mailto:live-devel at lists.live555.com>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.live555.com/pipermail/live-devel/attachments/20210809/9c7bfcee/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: image001.png
Type: image/png
Size: 100794 bytes
Desc: image001.png
URL: <http://lists.live555.com/pipermail/live-devel/attachments/20210809/9c7bfcee/attachment-0001.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: UAF_MPG_poc.zip
Type: application/x-zip-compressed
Size: 1424 bytes
Desc: UAF_MPG_poc.zip
URL: <http://lists.live555.com/pipermail/live-devel/attachments/20210809/9c7bfcee/attachment-0001.bin>

More information about the live-devel mailing list