<div style="font-family: system-ui; font-size: 14px"><div><br></div><div>Hello,
My name is Sangjun Park, and I am a fuzzing researcher. <br>I have identified a heap use-after-free (UAF) vulnerability in the live555 streaming media server (version 2024-09-29) running on Ubuntu 20.04. <br><br>
The issue occurs when the server processes a sequence of SETUP -> PLAY -> DESCRIBE requests from a client, leading to a heap UAF condition. <br><br>You can easily reproduce the bug by following the instructions in the attached README.md file. <br>
Additionally, I have included the ASAN report and a reproduction file, which you can access at the following link: https://drive.google.com/file/d/1uq6NFkCgxOcYkkUJtnr2DzMKdoWMZ-Tp/view?usp=sharing <br>
<br>Best regards, <br>Sangjun Park
</div><!-- begin signature --><!-- end signature --></div><!--[if mso]>
<table style ="display:none"><tr><td><img src="https://kaist.gov-dooray.com/mail-receipts?img=547a6c4559534836-32e091651d6fe486-3644720cc747b55e-3644720ec9f2cbc6.gif" border="0"></td></tr></table>
<![endif]-->
<!--[if !mso]><!-- -->
<table style ="visibility: hidden;"><tr><td><img src="https://kaist.gov-dooray.com/mail-receipts?img=547a6c4559534836-32e091651d6fe486-3644720cc747b55e-3644720ec9f2cbc6.gif" border="0"></td></tr></table>
<!--[endif]-->