CVE-2024-44331
published 2024-10-22CVE-2024-44331: Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of…
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.66%
47.4th percentile
Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gst-rtsp-server1.0 | < gst-rtsp-server1.0 1.24.9-1 (forky) | gst-rtsp-server1.0 1.24.9-1 (forky) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qfwh-xw3f-gfh2: Incorrect Access Control in GStreamer RTSP server 1
ghsa_unreviewed·2024-10-23
CVE-2024-44331 [HIGH] CWE-120 GHSA-qfwh-xw3f-gfh2: Incorrect Access Control in GStreamer RTSP server 1
Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.
OSV
CVE-2024-44331: Incorrect Access Control in GStreamer RTSP server 1
osv·2024-10-22·CVSS 7.5
CVE-2024-44331 [HIGH] CVE-2024-44331: Incorrect Access Control in GStreamer RTSP server 1
Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.
Red Hat
gstreamer1-rtsp-server: DoS via rtsp-media.c
vendor_redhat·2024-10-22·CVSS 7.5
CVE-2024-44331 [HIGH] CWE-617 gstreamer1-rtsp-server: DoS via rtsp-media.c
gstreamer1-rtsp-server: DoS via rtsp-media.c
Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.
A flaw was found in GStreamer RTSP server. In certain versions, specially-crafted requests may trigger an assertion failure in the server, which can lead to a denial of service.
Statement: This vulnerability in the GStreamer RTSP server is classified as moderate rather than important because, while it can cause a denial of service (DoS), it does not allow remote code execution, privilege escalation, or data exposure. The flaw relies on sending specially crafted hexstream requests to disrupt the service, which may affect availability but does not comp
Debian
CVE-2024-44331: gst-rtsp-server1.0 - Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp...
vendor_debian·2024·CVSS 7.5
CVE-2024-44331 [HIGH] CVE-2024-44331: gst-rtsp-server1.0 - Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp...
Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.24.9-1)
sid: resolved (fixed in 1.24.9-1)
trixie: resolved (fixed in 1.24.9-1)
No detection rules found.
No public exploits indexed.
2024-10-22
Published