{"id":"MGASA-2019-0121","summary":"Updated live, mplayer, vlc packages fix security vulnerability","details":"The updated live, mplayer, vlc packages fix security vulnerabilities:\n\nliblivemedia in Live555 before 2019.02.03 mishandles the termination of an\nRTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to\na Use-After-Free error that causes the RTSP server to crash (Segmentation\nfault) or possibly have unspecified other impact. (CVE-2019-7314)\n\nIn Live555 before 2019.02.27, malformed headers lead to invalid memory\naccess in the parseAuthorizationHeader function. (CVE-2019-9215)\n\nMplayer and VLC has been rebuilt against new live packages.\n\nAlso, VLC has been updated to version 3.0.6.\n","modified":"2026-04-16T04:42:58.276681107Z","published":"2019-03-29T15:51:06Z","upstream":["CVE-2019-7314","CVE-2019-9215"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0121.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=24527"},{"type":"WEB","url":"https://www.debian.org/security/2019/dsa-4408"},{"type":"WEB","url":"https://www.videolan.org/developers/vlc-branch/NEWS"},{"type":"WEB","url":"http://live555.com/liveMedia/public/changelog.txt"}],"affected":[{"package":{"name":"live","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/live?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2019.03.06-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0121.json"}},{"package":{"name":"mplayer","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/mplayer?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.0-14.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0121.json"}},{"package":{"name":"vlc","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/vlc?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.6-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0121.json"}},{"package":{"name":"mplayer","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/mplayer?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.0-14.mga6.tainted"}]}],"ecosystem_specific":{"section":"tainted"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0121.json"}},{"package":{"name":"vlc","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/vlc?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.6-1.mga6.tainted"}]}],"ecosystem_specific":{"section":"tainted"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0121.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}