UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/0pepsi/CVE-2025-60458 |
|
History
Mon, 29 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
cvssV3_1
|
Mon, 29 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-29T16:46:50.304Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60458
Updated: 2025-12-29T16:46:45.440Z
Status : Awaiting Analysis
Published: 2025-12-29T15:16:01.520
Modified: 2025-12-29T17:15:45.710
Link: CVE-2025-60458
No data.
OpenCVE Enrichment
No data.