An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "15.0-sp1"
}
],
"source": "CPE_STRING",
"vendor_product": "opensuse:backports_sle"
},
{
"cpes": [
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "15.1"
}
],
"source": "CPE_STRING",
"vendor_product": "opensuse:leap"
}
]
}{
"cpe": "cpe:2.3:a:gstreamer_project:gst-rtsp-server:1.14.5:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.14.5"
}
],
"source": "CPE_STRING"
}"2026-05-30T16:11:03Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-6095.json"
[
{
"digest": {
"length": 974.0,
"function_hash": "321621454934023608561527569629519791371"
},
"deprecated": false,
"id": "CVE-2020-6095-4e4940d4",
"signature_version": "v1",
"source": "https://gitlab.freedesktop.org/gstreamer/gst-rtsp-server@44ccca3086dd81081d72ca0b21d0ecdde962fb1a",
"signature_type": "Function",
"target": {
"function": "default_authenticate",
"file": "gst/rtsp-server/rtsp-auth.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"69347512028647998947647989890702729393",
"169785759834100554059797340295832875417",
"232724341315295775364387316451114592560",
"243056517678594786714431000077397043096"
]
},
"deprecated": false,
"id": "CVE-2020-6095-c132ca9b",
"signature_version": "v1",
"source": "https://gitlab.freedesktop.org/gstreamer/gst-rtsp-server@44ccca3086dd81081d72ca0b21d0ecdde962fb1a",
"signature_type": "Line",
"target": {
"file": "gst/rtsp-server/rtsp-auth.c"
}
}
]