CVE-2014-3970

The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of service (assertion failure and abort) via an empty UDP packet.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pulseaudio:pulseaudio:1.0:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio:pulseaudio:1.1:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio:pulseaudio:1.99.1:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio:pulseaudio:1.99.2:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio:pulseaudio:2.0:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio:pulseaudio:2.1:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio:pulseaudio:3.0:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio:pulseaudio:4.0:*:*:*:*:*:*:*
cpe:2.3:a:pulseaudio:pulseaudio:5.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:09

Type Values Removed Values Added
References () http://advisories.mageia.org/MGASA-2014-0440.html - () http://advisories.mageia.org/MGASA-2014-0440.html -
References () http://lists.freedesktop.org/archives/pulseaudio-discuss/2014-May/020740.html - Exploit () http://lists.freedesktop.org/archives/pulseaudio-discuss/2014-May/020740.html - Exploit
References () http://seclists.org/oss-sec/2014/q2/429 - () http://seclists.org/oss-sec/2014/q2/429 -
References () http://seclists.org/oss-sec/2014/q2/437 - () http://seclists.org/oss-sec/2014/q2/437 -
References () http://secunia.com/advisories/60624 - () http://secunia.com/advisories/60624 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2015:134 - () http://www.mandriva.com/security/advisories?name=MDVSA-2015:134 -
References () http://www.securityfocus.com/bid/67814 - () http://www.securityfocus.com/bid/67814 -

Information

Published : 2014-06-11 14:55

Updated : 2024-11-21 02:09


NVD link : CVE-2014-3970

Mitre link : CVE-2014-3970

CVE.ORG link : CVE-2014-3970


JSON object : View

Products Affected

pulseaudio

  • pulseaudio