Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f48p-mg4r-fhww

Опубликовано: 09 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

EPSS

Процентиль: 23%
0.0031
Низкий

7.5 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 7.5
ubuntu
22 дня назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
redhat
24 дня назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
nvd
22 дня назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.

CVSS3: 7.5
debian
22 дня назад

A stack buffer overflow vulnerability was found in GStreamer's DTLS pl ...

oracle-oval
4 дня назад

ELSA-2026-47180: gstreamer1-plugins-bad-free security update (IMPORTANT)

EPSS

Процентиль: 23%
0.0031
Низкий

7.5 High

CVSS3

Дефекты

CWE-121