Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and srtp_protect functions.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libsrtp-develUpgrade libsrtp-debuginfoUpgrade libsrtp | Oct 28, 2020 | Jan 16, 2014 |
| Centos_linux | — | Upgrade libsrtp-debuginfoUpgrade libsrtp-develUpgrade libsrtp | Oct 1, 2020 | Jan 16, 2014 |
| Gentoo Linux | — | Upgrade net-libs/libsrtp. | Oct 30, 2017 | Jan 16, 2014 |
| Huawei Euleros 2_0_sp2 | — | Upgrade libsrtp | Dec 4, 2019 | Jan 16, 2014 |
| Huawei Euleros 2_0_sp3 | — | Upgrade libsrtp | Dec 18, 2019 | Jan 16, 2014 |
| Huawei Euleros 2_0_sp5 | — | Upgrade libsrtp | Dec 27, 2019 | Jan 16, 2014 |
| Oracle_linux | — | Upgrade libsrtpUpgrade libsrtp-devel | Oct 13, 2020 | Jan 16, 2014 |
| Redhat_linux | — | Upgrade libsrtpUpgrade libsrtp-develUpgrade libsrtp-debuginfo | Oct 1, 2020 | Jan 16, 2014 |
| Suse | — | Upgrade srtpUpgrade srtp-develUpgrade libsrtp1 | Dec 12, 2013 | Dec 10, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub