CVE Vulnerabilities

CVE-2014-3970

Published: Jun 11, 2014 | Modified: Jan 07, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.9 LOW
AV:A/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
1.8 LOW
AV:A/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of service (assertion failure and abort) via an empty UDP packet.

Affected Software

Name Vendor Start Version End Version
Pulseaudio Pulseaudio 1.0 (including) 1.0 (including)
Pulseaudio Pulseaudio 1.1 (including) 1.1 (including)
Pulseaudio Pulseaudio 1.99.1 (including) 1.99.1 (including)
Pulseaudio Pulseaudio 1.99.2 (including) 1.99.2 (including)
Pulseaudio Pulseaudio 2.0 (including) 2.0 (including)
Pulseaudio Pulseaudio 2.1 (including) 2.1 (including)
Pulseaudio Pulseaudio 3.0 (including) 3.0 (including)
Pulseaudio Pulseaudio 4.0 (including) 4.0 (including)
Pulseaudio Pulseaudio 5.0 (including) 5.0 (including)
Pulseaudio Ubuntu artful *
Pulseaudio Ubuntu lucid *
Pulseaudio Ubuntu precise *
Pulseaudio Ubuntu saucy *
Pulseaudio Ubuntu trusty *
Pulseaudio Ubuntu utopic *
Pulseaudio Ubuntu vivid *
Pulseaudio Ubuntu vivid/stable-phone-overlay *
Pulseaudio Ubuntu wily *
Pulseaudio Ubuntu yakkety *
Pulseaudio Ubuntu zesty *

References