Back

HIGH

gstreamer1-rtsp-server: DoS via rtsp-media.c

Published Oct 22, 2024

Description

Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted hexstream requests.

Affected products

Remediation

Red Hat statement

This vulnerability in the GStreamer RTSP server is classified as moderate rather than important because, while it can cause a denial of service (DoS), it does not allow remote code execution, privilege escalation, or data exposure. The flaw relies on sending specially crafted hexstream requests to disrupt the service, which may affect availability but does not compromise the integrity or confidentiality of the system. Moreover, the impact is limited to crashing or temporarily disrupting the RTSP server, with no lasting damage or persistent effects once the server is restarted. It's important to note that this vulnerability does not impact any Red Hat products, indicating that Red Hat's software stack is unaffected by this specific CVE.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 22, 2024
Updated Oct 23, 2024
Reserved Aug 21, 2024
CISA Vulnrichment
Updated Oct 23, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 22, 2024