CVE Vulnerabilities

CVE-2014-3970

Published: Jun 11, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.9 LOW
AV:A/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
1.8 LOW
AV:A/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of service (assertion failure and abort) via an empty UDP packet.

Affected Software

NameVendorStart VersionEnd Version
PulseaudioPulseaudio1.0 (including)1.0 (including)
PulseaudioPulseaudio1.1 (including)1.1 (including)
PulseaudioPulseaudio1.99.1 (including)1.99.1 (including)
PulseaudioPulseaudio1.99.2 (including)1.99.2 (including)
PulseaudioPulseaudio2.0 (including)2.0 (including)
PulseaudioPulseaudio2.1 (including)2.1 (including)
PulseaudioPulseaudio3.0 (including)3.0 (including)
PulseaudioPulseaudio4.0 (including)4.0 (including)
PulseaudioPulseaudio5.0 (including)5.0 (including)
PulseaudioUbuntuartful*
PulseaudioUbuntulucid*
PulseaudioUbuntuprecise*
PulseaudioUbuntusaucy*
PulseaudioUbuntutrusty*
PulseaudioUbuntuutopic*
PulseaudioUbuntuvivid*
PulseaudioUbuntuvivid/stable-phone-overlay*
PulseaudioUbuntuwily*
PulseaudioUbuntuyakkety*
PulseaudioUbuntuzesty*

References