Gentoo Archives: gentoo-announce

From: Sean Amoss <ackle@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201405-02 ] libSRTP: Denial of Service
Date: Sat, 03 May 2014 13:48:56
Message-Id: 5364F30F.7000205@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201405-02
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: libSRTP: Denial of Service
9 Date: May 03, 2014
10 Bugs: #472302
11 ID: 201405-02
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A vulnerability in libSRTP can result in a Denial of Service condition.
19
20 Background
21 ==========
22
23 libSRTP is an Open-source implementation of the Secure Real-time
24 Transport Protocol.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-libs/libsrtp < 1.4.4_p20121108-r1>= 1.4.4_p20121108-r1
33
34 Description
35 ===========
36
37 A flaw was found in how the crypto_policy_set_from_profile_for_rtp()
38 function applies cryptographic profiles to an srtp_policy in libSRTP.
39
40 Impact
41 ======
42
43 A remote attacker could exploit this vulnerability to crash an
44 application linked against libSRTP, resulting in Denial of Service.
45
46 Workaround
47 ==========
48
49 There is no known workaround at this time.
50
51 Resolution
52 ==========
53
54 All libSRTP users should upgrade to the latest version:
55
56 # emerge --sync
57 # emerge --ask --oneshot -v ">=net-libs/libsrtp-1.4.4_p20121108-r1"
58
59 References
60 ==========
61
62 [ 1 ] CVE-2013-2139
63 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2139
64
65 Availability
66 ============
67
68 This GLSA and any updates to it are available for viewing at
69 the Gentoo Security Website:
70
71 http://security.gentoo.org/glsa/glsa-201405-02.xml
72
73 Concerns?
74 =========
75
76 Security is a primary focus of Gentoo Linux and ensuring the
77 confidentiality and security of our users' machines is of utmost
78 importance to us. Any security concerns should be addressed to
79 security@g.o or alternatively, you may file a bug at
80 https://bugs.gentoo.org.
81
82 License
83 =======
84
85 Copyright 2014 Gentoo Foundation, Inc; referenced text
86 belongs to its owner(s).
87
88 The contents of this document are licensed under the
89 Creative Commons - Attribution / Share Alike license.
90
91 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature