Wiz Agents & Workflows are here

CVE-2021-28899
Linux Debian vulnerability analysis and mitigation

Overview

A vulnerability was discovered in Networks LIVE555 Streaming Media before version 2021.3.16, affecting the AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsession subclasses. The vulnerability was disclosed on March 16, 2021, and assigned CVE-2021-28899. The issue affects RTSP server implementations using specific OnDemandServerMediaSubsession subclasses (Live555 Advisory).

Technical details

The vulnerability received a CVSS v3.1 base score of 7.5 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). The issue specifically impacts RTSP servers implementing certain OnDemandServerMediaSubsession subclasses, including AC3AudioFileServerMediaSubsession, ADTSAudioFileServerMediaSubsession, and AMRAudioFileServerMediaSubsession. The DynamicRTSPServer code used by the LIVE555 Media Server is not affected by this vulnerability (NVD).

Impact

The vulnerability can lead to high availability impact on affected systems, as indicated by the CVSS metrics. The vulnerability affects the system's availability while having no direct impact on confidentiality or integrity (NVD).

Mitigation and workarounds

Users are advised to upgrade to LIVE555 Streaming Media version 2021.03.16 or later. This is particularly important for implementations using the affected OnDemandServerMediaSubsession subclasses. Note that the DynamicRTSPServer code used by the LIVE555 Media Server is not vulnerable to this issue (Live555 Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-33986HIGH7.5
  • WolfiWolfi
  • freerdp2
NoYesMar 30, 2026
CVE-2026-33987HIGH7.1
  • WolfiWolfi
  • freerdp2
NoYesMar 30, 2026
CVE-2026-33995MEDIUM5.3
  • WolfiWolfi
  • libwinpr
NoYesMar 30, 2026
CVE-2026-34881MEDIUM5
  • Linux DebianLinux Debian
  • glance
NoYesMar 31, 2026
CVE-2026-33691N/AN/A
  • Linux DebianLinux Debian
  • modsecurity-crs
NoNoMar 31, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management