CVE-2013-2139
published 2014-01-16CVE-2013-2139: Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length…
PriorityP417low2.6CVSS 2.0
AVNACHAuNCNINAP
EPSS
2.99%
85.8th percentile
Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and srtp_protect functions.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | libsrtp | <= 1.4.5 | — |
| cisco | libsrtp | — | — |
| cisco | libsrtp | — | — |
| cisco | libsrtp | — | — |
| cisco | libsrtp | — | — |
| cisco | libsrtp | — | — |
| cisco | libsrtp | — | — |
| cisco | libsrtp | — | — |
| cisco | libsrtp | — | — |
| cisco | libsrtp | — | — |
| cisco | libsrtp | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p6g5-gwj7-cvr6: Buffer overflow in srtp
ghsa_unreviewed·2022-05-14
CVE-2013-2139 [LOW] CWE-119 GHSA-p6g5-gwj7-cvr6: Buffer overflow in srtp
Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and srtp_protect functions.
Red Hat
libsrtp: buffer overflow in application of crypto profiles
vendor_redhat·2013-05-30·CVSS 2.6
CVE-2013-2139 [LOW] libsrtp: buffer overflow in application of crypto profiles
libsrtp: buffer overflow in application of crypto profiles
Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and srtp_protect functions.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2014-0465.htmlhttp://lists.opensuse.org/opensuse-updates/2013-07/msg00083.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00059.htmlhttp://lwn.net/Articles/579633/http://seclists.org/fulldisclosure/2013/Jun/10http://www.debian.org/security/2014/dsa-2840http://www.mandriva.com/security/advisories?name=MDVSA-2014:219http://www.osvdb.org/93852https://bugzilla.redhat.com/show_bug.cgi?id=970697https://github.com/cisco/libsrtp/pull/27http://advisories.mageia.org/MGASA-2014-0465.htmlhttp://lists.opensuse.org/opensuse-updates/2013-07/msg00083.htmlhttp://lists.opensuse.org/opensuse-updates/2014-09/msg00059.htmlhttp://lwn.net/Articles/579633/http://seclists.org/fulldisclosure/2013/Jun/10http://www.debian.org/security/2014/dsa-2840http://www.mandriva.com/security/advisories?name=MDVSA-2014:219http://www.osvdb.org/93852https://bugzilla.redhat.com/show_bug.cgi?id=970697https://github.com/cisco/libsrtp/pull/27
2014-01-16
Published