Vulnerability Name:

CVE-2019-15784 (CCN-166170)

Assigned:2019-08-27
Published:2019-08-27
Updated:2020-08-24
Summary:Secure Reliable Transport (SRT) through 1.3.4 has a CSndUList array overflow if there are many SRT connections.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-129
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2019-15784

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:2083

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2019:2128

Source: XF
Type: UNKNOWN
srt-cve201915784-bo(166170)

Source: CCN
Type: SRT GIT Repository
Potential CSndUList array overflow #811

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://github.com/Haivision/srt/pull/811

Vulnerable Configuration:Configuration 1:
  • cpe:/a:srtalliance:secure_reliable_transport:*:*:*:*:*:*:*:* (Version <= 1.3.4)

  • Configuration CCN 1:
  • cpe:/a:srtalliance:secure_reliable_transport:1.3.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201915784
    V
    CVE-2019-15784
    2023-06-22
    oval:org.opensuse.security:def:7964
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:93464
    P
    (Important)
    2022-07-06
    oval:org.opensuse.security:def:3341
    P
    python-doc-2.7.13-28.31.2 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94971
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1724
    P
    Security update for tomcat (Important)
    2022-03-14
    oval:org.opensuse.security:def:112850
    P
    libsrt1_4-1.4.3-1.3 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106313
    P
    libsrt1_4-1.4.3-1.3 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:63244
    P
    uuidd-2.33.1-2.14 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63470
    P
    finch-2.13.0-10.105 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:1254
    P
    unixODBC-2.3.6-3.2.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62813
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100794
    P
    bluez-5.55-1.57 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101219
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72532
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:74359
    P
    Security update for bluez (Moderate)
    2021-07-12
    oval:org.opensuse.security:def:1610
    P
    Security update for pam_radius (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:66761
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:70012
    P
    Security update for ldb (Important)
    2021-03-24
    oval:org.opensuse.security:def:63106
    P
    python3-paramiko-2.4.1-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62448
    P
    libjbig2-32bit-2.1-1.31 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72418
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:117018
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62625
    P
    file-roller-3.32.5-1.8 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107460
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62424
    P
    libSDL2-2_0-0-2.0.8-1.34 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62904
    P
    kernel-docs-4.12.14-195.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:94081
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62425
    P
    libXcursor1-32bit-1.1.15-1.18 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62699
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:64181
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:63931
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:64293
    P
    libHX-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70117
    P
    libsrt1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49641
    P
    ibus on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64037
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:73452
    P
    libsrt1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74233
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66669
    P
    docker-libnetwork on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64139
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:49695
    P
    libsrt1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73334
    P
    unixODBC on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63797
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:100177
    P
    (Moderate)
    2019-11-28
    oval:org.opensuse.security:def:109983
    P
    Security update for srt (Moderate)
    2019-09-07
    oval:com.ubuntu.disco:def:2019157840000000
    V
    CVE-2019-15784 on Ubuntu 19.04 (disco) - low.
    2019-08-29
    BACK
    srtalliance secure reliable transport *
    srtalliance secure reliable transport 1.3.4