CVE-2013-2223

critical

Description

GNU ZRTPCPP before 3.2.0 allows remote attackers to obtain sensitive information (uninitialized heap memory) or cause a denial of service (out-of-bounds read) via a crafted packet, as demonstrated by a truncated Ping packet that is not properly handled by the getEpHash function.

References

https://github.com/wernerd/ZRTPCPP/commit/4654f330317c9948bb61d138eb24d49690ca4637

http://security.gentoo.org/glsa/glsa-201309-13.xml

http://secunia.com/advisories/54998

http://secunia.com/advisories/53818

http://seclists.org/oss-sec/2013/q2/638

http://lists.opensuse.org/opensuse-updates/2013-10/msg00053.html

http://lists.opensuse.org/opensuse-updates/2013-10/msg00052.html

Details

Source: Mitre, NVD

Published: 2013-10-04

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 5.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Severity: Critical