CVE-2020-6095
published 2020-03-27CVE-2020-6095: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.87%
85.2th percentile
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gst-rtsp-server1.0 | < gst-rtsp-server1.0 1.16.2-3 (bookworm) | gst-rtsp-server1.0 1.16.2-3 (bookworm) |
| gstreamer_project | gst-rtsp-server | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f5m8-wgfv-369r: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1
ghsa_unreviewed·2022-05-24
CVE-2020-6095 [MEDIUM] CWE-476 GHSA-f5m8-wgfv-369r: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
OSV
CVE-2020-6095: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1
osv·2020-03-27·CVSS 7.5
CVE-2020-6095 [HIGH] CVE-2020-6095: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
Debian
CVE-2020-6095: gst-rtsp-server1.0 - An exploitable denial of service vulnerability exists in the GstRTSPAuth functio...
vendor_debian·2020·CVSS 7.5
CVE-2020-6095 [HIGH] CVE-2020-6095: gst-rtsp-server1.0 - An exploitable denial of service vulnerability exists in the GstRTSPAuth functio...
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 1.16.2-3)
bullseye: resolved (fixed in 1.16.2-3)
forky: resolved (fixed in 1.16.2-3)
sid: resolved (fixed in 1.16.2-3)
trixie: resolved (fixed in 1.16.2-3)
Suricata
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2006-6095 [HIGH] ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID INSERT
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID INSERT"; flow:established,to_server; http.uri; content:"/activenews_view.asp?"; nocase; content:"articleID="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2006-6095; reference:url,www.securityfocus.com/bid/21167; classtype:web-application-attack; sid:2007478; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA00
Suricata
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2006-6095 [HIGH] ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID ASCII
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID ASCII"; flow:established,to_server; http.uri; content:"/activenews_view.asp?"; nocase; content:"articleID="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2006-6095; reference:url,www.securityfocus.com/bid/21167; classtype:web-application-attack; sid:2007480; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA00
Suricata
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-6095 [HIGH] ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID SELECT
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID SELECT"; flow:established,to_server; http.uri; content:"/activenews_view.asp?"; nocase; content:"articleID="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2006-6095; reference:url,www.securityfocus.com/bid/21167; classtype:web-application-attack; sid:2007476; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA00
Suricata
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2006-6095 [HIGH] ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID UPDATE
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID UPDATE"; flow:established,to_server; http.uri; content:"/activenews_view.asp?"; nocase; content:"articleID="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2006-6095; reference:url,www.securityfocus.com/bid/21167; classtype:web-application-attack; sid:2007481; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA000
Suricata
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2006-6095 [HIGH] ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID DELETE
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID DELETE"; flow:established,to_server; http.uri; content:"/activenews_view.asp?"; nocase; content:"articleID="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2006-6095; reference:url,www.securityfocus.com/bid/21167; classtype:web-application-attack; sid:2007479; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA00
Suricata
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2006-6095 [HIGH] ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID UNION SELECT
ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ActiveNews Manager SQL Injection Attempt -- activenews_view.asp articleID UNION SELECT"; flow:established,to_server; http.uri; content:"/activenews_view.asp?"; nocase; content:"articleID="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2006-6095; reference:url,www.securityfocus.com/bid/21167; classtype:web-application-attack; sid:2007477; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_t
No public exploits indexed.
Talos
Vulnerability Spotlight: Denial-of-service vulnerability in GStreamer
blogs_talos·2020-03-23·CVSS 7.5
[HIGH] Vulnerability Spotlight: Denial-of-service vulnerability in GStreamer
## Vulnerability Spotlight: Denial-of-service vulnerability in GStreamer
Peter Wang of Cisco ASIG discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a denial-of-service vulnerability in GStreamer, a pipeline-based
multimedia framework. GStreamer contains gst-rtsp-server, an open-source library that allows the user to build RTSP servers. This function contains an exploit that an attacker could use to cause a null pointer deference, resulting in a denial of service.
In accordance with our coordinated disclosure policy, Cisco Talos worked with GStreamer to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details GStreamer gst-rtsp-server GstRTSPAuth denial-of-service vulnerability (TALOS-2020-1
Talos
Vulnerability Spotlight: Denial-of-service vulnerability in GStreamer
blogs_talos·2020-03-23·CVSS 7.5
[HIGH] Vulnerability Spotlight: Denial-of-service vulnerability in GStreamer
Peter Wang of Cisco ASIG discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a denial-of-service vulnerability in GStreamer, a pipeline-based
multimedia framework. GStreamer contains gst-rtsp-server, an open-source library that allows the user to build RTSP servers. This function contains an exploit that an attacker could use to cause a null pointer deference, resulting in a denial of service.
In accordance with our coordinated disclosure policy, Cisco Talos worked with GStreamer to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detailsGStreamer gst-rtsp-server GstRTSPAuth denial-of-service vulnerability (TALOS-2020-1018/CVE-2020-6095)
An exploitable denial-of-service vulnerability exists
http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00029.htmlhttps://gitlab.freedesktop.org/gstreamer/gst-rtsp-server/-/commit/44ccca3086dd81081d72ca0b21d0ecdde962fb1ahttps://security.gentoo.org/glsa/202009-05https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1018http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00029.htmlhttps://gitlab.freedesktop.org/gstreamer/gst-rtsp-server/-/commit/44ccca3086dd81081d72ca0b21d0ecdde962fb1ahttps://security.gentoo.org/glsa/202009-05https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1018
2020-03-27
Published