MGASA-2021-0313

Source
https://advisories.mageia.org/MGASA-2021-0313.html
Import Source
https://advisories.mageia.org/MGASA-2021-0313.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0313
Related
Published
2021-07-04T02:13:55Z
Modified
2026-02-04T04:36:17.868459Z
Summary
Updated live packages fix security vulnerabilities
Details

Updated live packages fix security vulnerabilities:

Live555 before 2019.08.16 has a Use-After-Free because GenericMediaServer::createNewClientSessionWithId can generate the same client session ID in succession, which is mishandled by the MPEG1or2 and Matroska file demultiplexors (CVE-2019-15232).

Vulnerability in the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsessionLive OnDemandServerMediaSubsession subclasses in Networks LIVE555 Streaming Media before 2021.3.16 (CVE-2021-28899).

The mplayer package has been rebuilt against the updated live package.

References
Credits

Affected packages

Mageia:7
live

Package

Name
live
Purl
pkg:rpm/mageia/live?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2021.06.25-1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0313.json"
mplayer

Package

Name
mplayer
Purl
pkg:rpm/mageia/mplayer?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4-1.1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0313.json"
mplayer

Package

Name
mplayer
Purl
pkg:rpm/mageia/mplayer?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4-1.1.mga7.tainted

Ecosystem specific

{
    "section": "tainted"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0313.json"
Mageia:8
live

Package

Name
live
Purl
pkg:rpm/mageia/live?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2021.06.25-1.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0313.json"
mplayer

Package

Name
mplayer
Purl
pkg:rpm/mageia/mplayer?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4-9.3.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0313.json"
mplayer

Package

Name
mplayer
Purl
pkg:rpm/mageia/mplayer?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4-9.3.mga8.tainted

Ecosystem specific

{
    "section": "tainted"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0313.json"