Incorrect Authorization Affecting liblivemedia package, versions <2026.09.23-dfsg-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.63% (48th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN14-LIBLIVEMEDIA-20511665
  • published5 Oct 2026
  • disclosed19 May 2026

Introduced: 19 May 2026

CVE-2026-41470  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade Debian:14 liblivemedia to version 2026.09.23-dfsg-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream liblivemedia package and not the liblivemedia package as distributed by Debian. See How to fix? for Debian:14 relevant fixed versions and status.

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attackers who obtain a valid Session token can issue PLAY and TEARDOWN commands from a second TCP connection without authentication, causing server crashes through virtual function call errors or disrupting active streams by terminating victim sessions.

CVSS Base Scores

version 3.1