UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/0pepsi/CVE-2025-60458 |
|
History
Fri, 09 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Antimof
Antimof uxplay |
|
| CPEs | cpe:2.3:a:antimof:uxplay:1.72:*:*:*:*:*:*:* | |
| Vendors & Products |
Antimof
Antimof uxplay |
Mon, 29 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
cvssV3_1
|
Mon, 29 Dec 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request can trigger multiple calls to free() on the same memory address, potentially causing a Denial of Service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-12-29T00:00:00.000Z
Updated: 2025-12-29T16:46:50.304Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60458
Updated: 2025-12-29T16:46:45.440Z
Status : Analyzed
Published: 2025-12-29T15:16:01.520
Modified: 2026-01-09T21:58:05.090
Link: CVE-2025-60458
No data.