An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.16.2-3", "binary_name": "gir1.2-gst-rtsp-server-1.0" }, { "binary_version": "1.16.2-3", "binary_name": "gstreamer1.0-rtsp" }, { "binary_version": "1.16.2-3", "binary_name": "gstreamer1.0-rtsp-dbg" }, { "binary_version": "1.16.2-3", "binary_name": "libgstrtspserver-1.0-0" }, { "binary_version": "1.16.2-3", "binary_name": "libgstrtspserver-1.0-0-dbg" }, { "binary_version": "1.16.2-3", "binary_name": "libgstrtspserver-1.0-dev" }, { "binary_version": "1.16.2-3", "binary_name": "libgstrtspserver-1.0-doc" } ] }