LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.
{
"binaries": [
{
"binary_name": "libbasicusageenvironment1",
"binary_version": "2016.02.09-1ubuntu0.1~esm1"
},
{
"binary_name": "libgroupsock8",
"binary_version": "2016.02.09-1ubuntu0.1~esm1"
},
{
"binary_name": "liblivemedia50",
"binary_version": "2016.02.09-1ubuntu0.1~esm1"
},
{
"binary_name": "libusageenvironment3",
"binary_version": "2016.02.09-1ubuntu0.1~esm1"
},
{
"binary_name": "livemedia-utils",
"binary_version": "2016.02.09-1ubuntu0.1~esm1"
}
]
}
{
"binaries": [
{
"binary_name": "libbasicusageenvironment1",
"binary_version": "2018.02.18-1ubuntu0.1~esm1"
},
{
"binary_name": "libgroupsock8",
"binary_version": "2018.02.18-1ubuntu0.1~esm1"
},
{
"binary_name": "liblivemedia62",
"binary_version": "2018.02.18-1ubuntu0.1~esm1"
},
{
"binary_name": "libusageenvironment3",
"binary_version": "2018.02.18-1ubuntu0.1~esm1"
},
{
"binary_name": "livemedia-utils",
"binary_version": "2018.02.18-1ubuntu0.1~esm1"
}
]
}
{
"binaries": [
{
"binary_name": "libbasicusageenvironment1",
"binary_version": "2020.01.19-1build1"
},
{
"binary_name": "libgroupsock8",
"binary_version": "2020.01.19-1build1"
},
{
"binary_name": "liblivemedia77",
"binary_version": "2020.01.19-1build1"
},
{
"binary_name": "libusageenvironment3",
"binary_version": "2020.01.19-1build1"
},
{
"binary_name": "livemedia-utils",
"binary_version": "2020.01.19-1build1"
}
]
}