peter bassill · operator
$ cve CVE-2019-7314 JSON

CVE-2019-7314

9.8
CRITICAL · CVSS 3.0 · EPSS 3.2% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation fault) or possibly have unspecified other impact.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.19% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploitnone known
Published2019-02-04
Last modified2026-06-17

Affected (2)

VendorProduct
debiandebian linux
live555streaming media

References

→ the Explorer  ·  watch your stack  ·  NVD