Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-44331

Опубликовано: 22 окт. 2024
Источник: debian
EPSS Низкий

Описание

Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-rtsp-server1.0fixed1.24.9-1package
gst-rtsp-server1.0no-dsabookwormpackage
gst-rtsp-server1.0postponedbullseyepackage

Примечания

  • https://gstreamer.freedesktop.org/security/sa-2024-0004.html

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/issues/3731

  • Introduced by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/16bc937ed95c85c9d02a314a3b065eebc575a97c (gst-rtsp-server-1.18.0)

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/7731

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f3e707c71c9a0c4dacc40168fe5c83f49ded846e (main)

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/cd8aede9f3000cd5387c1a17d60796d5a3cee96c (1.24.9)

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/aa3e97d67c05d4648ea58c7ff7675e24a81ca72b (1.22-branch)

EPSS

Процентиль: 67%
0.00531
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.

CVSS3: 7.5
redhat
около 1 года назад

Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.

CVSS3: 7.5
nvd
около 1 года назад

Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.

CVSS3: 7.5
github
около 1 года назад

Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.

EPSS

Процентиль: 67%
0.00531
Низкий