Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-59692

Опубликовано: 09 июл. 2026
Источник: debian
EPSS Низкий

Описание

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gst-plugins-bad1.0fixed1.28.5-1package
gst-plugins-bad1.0no-dsatrixiepackage

Примечания

  • https://gstreamer.freedesktop.org/security/sa-2026-0062.html

  • https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12053

  • Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/9bb455393b8ccb48e63027f3e30285f80cf3762c (1.28.5)

EPSS

Процентиль: 46%
0.00577
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
redhat
3 месяца назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
nvd
3 месяца назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
redos
3 дня назад

Уязвимость gstreamer1-plugins-bad-freeworld

CVSS3: 7.5
redos
3 дня назад

Уязвимость gstreamer1-plugins-bad-free

EPSS

Процентиль: 46%
0.00577
Низкий