GStreamer是GStreamer组织开源的一套用于处理流媒体的框架。 GStreamer存在处理逻辑错误漏洞,该漏洞源于GStreamer的webrtcbin组件中_check_sdp_crypto()函数存在反转的布尔条件,导致接受缺少所需a=fingerprint属性的远程SDP提议或答案,同时错误拒绝包含该属性的SDP,可能被拦截和修改WebRTC信令消息的攻击者利用,绕过SDP级别的DTLS证书指纹绑定,削弱媒体流中间人攻击防御。以下版本受到影响:Red Hat Enterprise Lin
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 6 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
any |
affected | ||
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14474 | 8.8 HIGH | Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by defa |
| CVE-2026-14476 | 8.0 HIGH | Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authen |
| CVE-2026-58384 | 7.3 HIGH | Gimp: gimp: integer overflow in read_rle_channel() |
| CVE-2025-12799 | 6.5 MEDIUM | Jastow: jastow cross-site scripting attack due to unsanitized uri |
| CVE-2026-14940 | 5.3 MEDIUM | 389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued |
| CVE-2026-14969 | 4.4 MEDIUM | 389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encry |
No comments yet