
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-44331 affects GStreamer RTSP server version 1.25.0, specifically in the gst-rtsp-server/rtsp-media.c component. The vulnerability was discovered and disclosed in October 2024, allowing remote attackers to cause a denial of service through incorrect access control (NVD, GitHub Gist).
The vulnerability exists in the gst_rtsp_media_get_rates function within gst-rtsp-server/rtsp-media.c. It has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The vulnerability is classified under CWE-120 (Buffer Copy without Checking Size of Input) (RedHat, NVD).
The vulnerability allows remote attackers to cause a denial of service condition in the GStreamer RTSP server. When successfully exploited, it affects the availability of the service without compromising the integrity or confidentiality of the system. The impact is limited to crashing or temporarily disrupting the RTSP server, with no lasting damage once the server is restarted (RedHat).
Currently, there is no official patch or mitigation strategy published for this vulnerability. Red Hat has noted that mitigation options are either not available or do not meet their Product Security criteria for ease of use and deployment (RedHat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."