MGASA-2014-0465

Source
https://advisories.mageia.org/MGASA-2014-0465.html
Import Source
https://advisories.mageia.org/MGASA-2014-0465.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0465
Upstream
  • CVE-2013-2139
Published
2014-11-21T12:44:16Z
Modified
2026-04-16T06:24:30Z
Summary
Updated srtp package fixes security vulnerability
Details

Fernando Russ from Groundworks Technologies reported a buffer overflow flaw in srtp, Cisco's reference implementation of the Secure Real-time Transport Protocol (SRTP), in how the crypto_policy_set_from_profile_for_rtp() function applies cryptographic profiles to an srtp_policy. A remote attacker could exploit this vulnerability to crash an application linked against libsrtp, resulting in a denial of service (CVE-2013-2139).

References
Credits

Affected packages

Mageia:3 / srtp

Package

Name
srtp
Purl
pkg:rpm/mageia/srtp?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.4.4-3.1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0465.json"