PT-2014-1764 · Wireshark+1 · Wireshark+1

Published

2014-04-23

·

Updated

2024-06-15

·

CVE-2014-2907

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Wireshark versions 1.10.x through 1.10.6
Description The issue exists in the srtp add address function in the RTP dissector due to incorrect updating of SRTP conversation data. This allows remote attackers to cause a denial of service, resulting in the application crashing when a specially crafted packet is received.
Recommendations For Wireshark versions 1.10.x through 1.10.6, update to version 1.10.7 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2014-1565
BDU:2015-00784
CVE-2014-2907
MGASA-2014-0195
OPENSUSE-SU-2024:10199-1

Affected Products

Alt Linux
Wireshark