4.3
CVSSv2

CVE-2014-2907

Published: 24/04/2014 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x prior to 1.10.7 does not properly update SRTP conversation data, which allows remote malicious users to cause a denial of service (application crash) via a crafted packet.

Vulnerable Product Search on Vulmon Subscribe to Product

wireshark wireshark 1.10.6

wireshark wireshark 1.10.0

wireshark wireshark 1.10.3

wireshark wireshark 1.10.2

wireshark wireshark 1.10.1

wireshark wireshark 1.10.4

wireshark wireshark 1.10.5

Vendor Advisories

Debian Bug report logs - #745595 wireshark: CVE-2014-2907: RTP dissector crash Package: wireshark; Maintainer for wireshark is Balint Reczey <rbalint@ubuntucom>; Source for wireshark is src:wireshark (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Date: Wed, 23 Apr 2014 07:12:02 UTC Severity: importan ...
The srtp_add_address function in epan/dissectors/packet-rtpc in the RTP dissector in Wireshark 110x before 1107 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet ...