srt -- Multiple vulnerabilities
| Affected packages |
|
|
srt |
< |
1.5.6 |
|
Details
| VuXML ID |
037b7b00-84d4-11f1-8f76-345a6001a2f9 |
| Discovery |
2026-07-20 |
| Entry |
2026-07-21 |
The SRT project reports:
- CVE-2026-55869: Heap-Based Buffer Overflow in KMREQ Handling.
A remote attacker may be able to trigger a heap-based buffer
overflow during key material request processing, leading to a
denial of service or potentially arbitrary code execution.
- CVE-2026-55868: Encryption State Machine Downgrade.
A flaw in the encryption state machine may allow an attacker to
downgrade the negotiated encryption, weakening confidentiality
protections for the SRT stream.
References
Copyright © 2003-2005 Jacques Vidrine and contributors.
Please see the source of this document for full copyright
information.