MGASA-2014-0465
Dashboard / Vulnerabilities / MGASA-2014-0465
Summary: Updated srtp package fixes security vulnerability
Details: Fernando Russ from Groundworks Technologies reported a buffer overflow flaw in srtp, Cisco's reference implementation of the Secure Real-time Transport Protocol (SRTP), in how the crypto_policy_set_from_profile_for_rtp() function applies cryptographic profiles to an srtp_policy. A remote attacker could exploit this vulnerability to crash an application linked against libsrtp, resulting in a denial of service (CVE-2013-2139).
References: https://advisories.mageia.org/MGASA-2014-0465.html, https://bugs.mageia.org/show_bug.cgi?id=14200, https://www.debian.org/security/2014/dsa-2840
Affected packages
Package
Name: srtp
Purl: pkg:rpm/mageia/srtp?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
