Bug 1168026 (CVE-2020-6095) - VUL-0: CVE-2020-6095: gstreamer-rtsp-server: denial of service vulnerability in the GstRTSPAuth functionality
Summary: VUL-0: CVE-2020-6095: gstreamer-rtsp-server: denial of service vulnerability ...
Status: RESOLVED FIXED
Alias: CVE-2020-6095
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.1
Hardware: Other Other
: P3 - Medium : Minor (vote)
Target Milestone: ---
Assignee: Bjørn Lie
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/256058/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2020-03-30 07:29 UTC by Wolfgang Frisch
Modified: 2023-08-03 11:41 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Frisch 2020-03-30 07:29:48 UTC
CVE-2020-6095

An exploitable denial of service vulnerability exists in the GstRTSPAuth
functionality of GStreamer/gst-rtsp-server 1.14.5. A specially crafted RTSP
setup request can cause a null pointer deference resulting in denial-of-service.
An attacker can send a malicious packet to trigger this vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-6095
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6095
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1018
Comment 1 Wolfgang Frisch 2020-03-30 07:34:16 UTC
Upstream commit: 44ccca3086dd81081d72ca0b21d0ecdde962fb1a

Affected:
openSUSE Tumbleweed
openSUSE Leap 15.1
openSUSE Leap 15.2
Comment 3 Bjørn Lie 2020-04-15 17:29:06 UTC
Fixed package checked into Factory

Subbed from factory to Leap 15.2

https://build.opensuse.org/request/show/794223

Maintenance acked sub for Sleap 15.1, not yet published though.

Closing as resolved fixed
Comment 4 Swamp Workflow Management 2020-04-17 19:16:29 UTC
openSUSE-SU-2020:0535-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1168026
CVE References: CVE-2020-6095
Sources used:
openSUSE Leap 15.1 (src):    gstreamer-rtsp-server-1.12.5-lp151.3.3.1
openSUSE Backports SLE-15-SP1 (src):    gstreamer-rtsp-server-1.12.5-bp151.4.3.1