FS#69316 - [live-media] [Security] arbitrary code execution (CVE-2020-24027)
Attached to Project:
Arch Linux
Opened by Jonas Witschel (diabonas) - Wednesday, 13 January 2021, 21:26 GMT
Last edited by Antonio Rojas (arojas) - Thursday, 29 April 2021, 22:04 GMT
Opened by Jonas Witschel (diabonas) - Wednesday, 13 January 2021, 21:26 GMT
Last edited by Antonio Rojas (arojas) - Thursday, 29 April 2021, 22:04 GMT
|
Details
Summary
======= The package live-media is vulnerable to arbitrary code execution via CVE-2020-24027. Guidance ======== Upgrading to any version >= 2020.07.09 (currently the latest version is 2021.01.13) fixes the issue. References ========== https://security.archlinux.org/AVG-1448 http://lists.live555.com/pipermail/live-devel/2020-July/021662.html http://lists.live555.com/pipermail/live-devel/2020-July/021663.html |
This task depends upon
Closed by Antonio Rojas (arojas)
Thursday, 29 April 2021, 22:04 GMT
Reason for closing: Fixed
Additional comments about closing: live-media 2021.04.06
Thursday, 29 April 2021, 22:04 GMT
Reason for closing: Fixed
Additional comments about closing: live-media 2021.04.06
Comment by
Jonas Witschel (diabonas) -
Thursday, 29 April 2021, 20:57 GMT
Another security issue (CVE-2021-28899), fixed in version >=
2021.3.16:
http://lists.live555.com/pipermail/live-devel/2021-March/021891.html