CVE-2019-6256: Debian Linux
Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP session. This occurs because of a call to an incorrect virtual function pointer in the readSocket function in GroupsockHelper.cpp.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- LIVE555 LIVE555 Media Server: version 0.93 only
Published 2019-01-14. Last modified 2026-06-17.