DSA-2840-1 srtp -- buffer overflowID: oval:org.secpod.oval:def:601192 | Date: (C)2014-02-06 (M)2022-10-10 |
Class: PATCH | Family: unix |
Fernando Russ from Groundworks Technologies reported a buffer overflow flaw in srtp, Cisco"s reference implementation of the Secure Real-time Transport Protocol , in how the crypto_policy_set_from_profile_for_rtp function applies cryptographic profiles to an srtp_policy. A remote attacker could exploit this vulnerability to crash an application linked against libsrtp, resulting in a denial of service.
Platform: |
Debian 7.0 |
Debian 6.0 |