[Live-devel] Heap Use-After-Free Bug(3) in live555 (2024-09-29)
박상준
sangjuns at kaist.ac.kr
Tue Oct 8 23:59:22 PDT 2024
Hello,
My name is Sangjun Park, and I am a fuzzing researcher. I have discovered a heap use-after-free (UAF) vulnerability in the live555 streaming media server (version 2024-09-29) running on Ubuntu 20.04.
The issue arises when the server handles a sequence of SETUP and other related client requests, leading to a heap UAF condition. You can easily reproduce the bug by following the steps provided in the attached README.md.
Additionally, I have attached the ASAN report and a reproducible test case, which you can access via the following link: https://drive.google.com/file/d/16KZK8IVF8ax2s5elZHXbMkVjLcGXnRxJ/view?usp=sharing
Best regards, Sangjun Park
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.live555.com/pipermail/live-devel/attachments/20241009/721bb601/attachment.htm>
More information about the live-devel
mailing list