PT-2016-3709 · Cisco+3 · Libsrtp+5

Randell Jesup

·

Published

2015-11-28

·

Updated

2024-06-15

·

CVE-2015-6360

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Cisco libSRTP versions prior to 1.5.3
Description The issue is related to the encryption-processing feature in Cisco libSRTP, which allows remote attackers to cause a denial of service via crafted fields in SRTP packets. This is due to improper input validation of certain fields of SRTP packets. An attacker could exploit this vulnerability by sending a crafted SRTP packet designed to trigger the issue to an affected device. The impact of this vulnerability on Cisco products may vary depending on the affected product.
Recommendations For versions prior to 1.5.3, update to version 1.5.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the encryption processing subsystem of libSRTP to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-2034
CESA-2020_3873
CVE-2015-6360
DLA-393-1
DSA-3539-1
MGASA-2016-0037
OPENSUSE-SU-2024:10265-1
OPENSUSE-SU-2024:10997-1
RHSA-2020:3873
RHSA-2020_3873

Affected Products

Alt Linux
Centos
Cisco Asa
Cisco Ios Xe
Red Hat
Libsrtp