漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token
Vulnerability Description
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
授权机制不正确
Vulnerability Title
Live555 安全漏洞
Vulnerability Description
Live555是一个为流媒体提供解决方案的跨平台的C++开源项目,它实现了对标准流媒体传输协议如RTP/RTCP、RTSP、SIP等的支持。 LIVE555 2026.04.22之前版本存在安全漏洞,该漏洞源于RTSP会话命令处理中存在授权绕过,允许攻击者从未经身份验证的连接重放有效的Session令牌,导致服务器崩溃或中断活动流。
CVSS Information
N/A
Vulnerability Type
N/A