The Bzrtp library (aka libbzrtp) 1.0.x before 1.0.4 allows man-in-the-middle attackers to conduct spoofing attacks by leveraging a missing HVI check on DHPart2 packet reception.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade bzrtp | Jul 30, 2024 | Jan 18, 2017 |
| Suse | — | Upgrade libbzrtp0-32bitUpgrade bzrtp-develUpgrade libbzrtp0Upgrade libbzrtp0-debuginfoUpgrade bzrtp-debugsourceUpgrade libbzrtp0-debuginfo-32bit | Feb 2, 2017 | Jan 18, 2017 |
| Ubuntu | — | Upgrade bzrtp | Nov 19, 2024 | Jan 18, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub