CVE-2020-6095 — Unchecked Return Value to NULL Pointer Dereference in Gstreamer
Severity
7.5HIGHNVD
EPSS
0.5%
top 32.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 27
Latest updateMay 24
Description
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages4 packages
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-f5m8-wgfv-369r: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1↗2022-05-24
OSV▶
CVE-2020-6095: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1↗2020-03-27
CVEList▶
CVE-2020-6095: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1↗2020-03-27
📋Vendor Advisories
1Debian▶
CVE-2020-6095: gst-rtsp-server1.0 - An exploitable denial of service vulnerability exists in the GstRTSPAuth functio...↗2020