CVE-2014-2907

Wireshark 1.10.x < 1.10.7 - Denial of Service via SRTP Conversation Data Update

Title source: llm
STIX 2.1

Description

The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

Scores

EPSS 0.0021
EPSS Percentile 42.5%

Details

Status published
Products (7)
wireshark/wireshark 1.10.0
wireshark/wireshark 1.10.1
wireshark/wireshark 1.10.2
wireshark/wireshark 1.10.3
wireshark/wireshark 1.10.4
wireshark/wireshark 1.10.5
wireshark/wireshark 1.10.6
Published Apr 24, 2014
Tracked Since Feb 18, 2026