An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
[
{
"id": "CVE-2020-6095-4e4940d4",
"deprecated": false,
"digest": {
"length": 974.0,
"function_hash": "321621454934023608561527569629519791371"
},
"target": {
"function": "default_authenticate",
"file": "gst/rtsp-server/rtsp-auth.c"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://gitlab.freedesktop.org/gstreamer/gst-rtsp-server@44ccca3086dd81081d72ca0b21d0ecdde962fb1a"
},
{
"id": "CVE-2020-6095-c132ca9b",
"deprecated": false,
"digest": {
"line_hashes": [
"69347512028647998947647989890702729393",
"169785759834100554059797340295832875417",
"232724341315295775364387316451114592560",
"243056517678594786714431000077397043096"
],
"threshold": 0.9
},
"target": {
"file": "gst/rtsp-server/rtsp-auth.c"
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://gitlab.freedesktop.org/gstreamer/gst-rtsp-server@44ccca3086dd81081d72ca0b21d0ecdde962fb1a"
}
]