An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP setup request can cause a null pointer deference resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.
{
"binaries": [
{
"binary_version": "1.14.5-0ubuntu1~18.04.1",
"binary_name": "gir1.2-gst-rtsp-server-1.0"
},
{
"binary_version": "1.14.5-0ubuntu1~18.04.1",
"binary_name": "gstreamer1.0-rtsp"
},
{
"binary_version": "1.14.5-0ubuntu1~18.04.1",
"binary_name": "libgstrtspserver-1.0-0"
},
{
"binary_version": "1.14.5-0ubuntu1~18.04.1",
"binary_name": "libgstrtspserver-1.0-dev"
}
]
}