PT-2026-102764 · Unknown · Netx Rtsp Server
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NetX RTSP Server (affected versions not specified)
Description
An unauthenticated client can cause a denial of service by draining the RTSP server's packet pool. This occurs when requests are sent containing a
Session header that the parser cannot convert. Specifically, the nx utility string to uint() function fails and returns a raw NetX error code instead of a mapped RTSP status code. This raw code is then passed to the nx rtsp server error response send() function, which fails to recognize it and returns without releasing the allocated response packet. Consequently, the packet block is not returned to the pool. A small number of such malformed requests can deplete the entire pool, causing the server and potentially the rest of the application stack to stop functioning.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netx Rtsp Server