Impact
A NULL pointer dereference flaw exists in GStreamer’s RTSP support library, triggered when parsing an Authorization or WWW‑Authenticate header that uses Digest authentication. Specially crafted whitespace around a parameter terminator can cause an internal length calculation to underflow, leading to a process crash. The result is a denial of service; there is no confirmed impact on confidentiality or integrity.
Affected Systems
The flaw affects Red Hat Enterprise Linux 7, 8, 9, and 10 systems that run the GStreamer RTSP library. No specific product version ranges are supplied, but any installation of GStreamer on these operating systems is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. EPSS data are not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is a remote, unauthenticated attacker who can send a single malformed RTSP request to a server or client that has RTSP enabled. Successful exploitation results in an application crash, causing service downtime, but does not grant the attacker access to data or system control.
OpenCVE Enrichment