UBUNTU-CVE-2017-14114
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-14114
Summary:
Details: RTPproxy through 2.2.alpha.20160822 has a NAT feature that results in not properly determining the IP address and port number of the legitimate recipient of RTP traffic, which allows remote attackers to obtain sensitive information or cause a denial of service (communication outage) via crafted RTP packets.
References: https://ubuntu.com/security/CVE-2017-14114, https://rtpbleed.com/, https://www.cve.org/CVERecord?id=CVE-2017-14114
Affected packages
Package
Name: rtpproxy
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
1.2.1-2.1ubuntu1
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
