← Back

CVE-2013-2139

nvd nist
Published: Jan 16, 2014Modified: Apr 29, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:N/I:N/A:P
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and srtp_protect functions.

Affected (16)

1 product
Fedora
1 product
Opensuse
1 product
Libsrtp
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 18
Version 19
Version 20
Opensuse
Version 12.3
Version 13.1
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Up to 1.4.5
Version 1.0.1
Version 1.0.2
Version 1.0.4
Version 1.0.5
Version 1.0.6
Version 1.3.20
Version 1.4.0
Version 1.4.1
Version 1.4.2
Version 1.4.4

References (20)

Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.