Candidate: CVE-2020-6095 PublicDate: 2020-03-27 20:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6095 https://talosintelligence.com/vulnerability_reports/TALOS-2020-1018 https://gitlab.freedesktop.org/gstreamer/gst-rtsp-server/-/commit/44ccca3086dd81081d72ca0b21d0ecdde962fb1a Description: An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_gst-rtsp-server1.0: upstream: https://gitlab.freedesktop.org/gstreamer/gst-rtsp-server/-/commit/44ccca3086dd81081d72ca0b21d0ecdde962fb1a upstream_gst-rtsp-server1.0: released (1.16.2-3) precise/esm_gst-rtsp-server1.0: DNE trusty_gst-rtsp-server1.0: ignored (out of standard support) trusty/esm_gst-rtsp-server1.0: DNE xenial_gst-rtsp-server1.0: ignored (end of standard support, was needs-triage) bionic_gst-rtsp-server1.0: needs-triage eoan_gst-rtsp-server1.0: ignored (reached end-of-life) focal_gst-rtsp-server1.0: not-affected (1.16.2-3) groovy_gst-rtsp-server1.0: not-affected (1.16.2-3) hirsute_gst-rtsp-server1.0: not-affected (1.16.2-3) impish_gst-rtsp-server1.0: not-affected (1.16.2-3) jammy_gst-rtsp-server1.0: not-affected (1.16.2-3) devel_gst-rtsp-server1.0: not-affected (1.16.2-3)