Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f48p-mg4r-fhww

Опубликовано: 09 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

EPSS

Процентиль: 46%
0.00577
Низкий

7.5 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
redhat
3 месяца назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
nvd
3 месяца назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
debian
3 месяца назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS pl ...

CVSS3: 7.5
redos
3 дня назад

Уязвимость gstreamer1-plugins-bad-freeworld

EPSS

Процентиль: 46%
0.00577
Низкий

7.5 High

CVSS3

Дефекты

CWE-121