CVE-2013-2139: Buffer Overflow

Published Jun 4, 2013
·
Updated

A buffer overflow flaw was reported [1] in libsrtp, Cisco's reference implementation of the Secure Real-time Transport Protocol (SRTP), in how the cryptopolicysetfromprofileforrtp() function applies cryptographic profiles to an srtppolicy. This could allow for a crash of a client linked against libsrtp (like asterisk or linphone).

A pull request in git [2] has a patch to correct this issue.

[1] http://seclists.org/fulldisclosure/2013/Jun/10 [2] https://github.com/cisco/libsrtp/pull/26

Other sources

Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the cryptopolicysetfromprofileforrtp and srtpprotect functions.

MITRE

Affected Software

16 affected components
Fedoraproject Fedora=18
Fedoraproject Fedora=19
Fedoraproject Fedora=20
openSUSE openSUSE=12.3
openSUSE openSUSE=13.1
Cisco libsrtp<=1.4.5
Cisco libsrtp=1.0.1
Cisco libsrtp=1.0.2
Cisco libsrtp=1.0.4
Cisco libsrtp=1.0.5
Cisco libsrtp=1.0.6
Cisco libsrtp=1.3.20
Cisco libsrtp=1.4.0
Cisco libsrtp=1.4.1
Cisco libsrtp=1.4.2
Cisco libsrtp=1.4.4

Event History

Jun 4, 2013
Data Sourced
via Red Hat·03:46 PM
DescriptionSeverityAffected Software
Jan 16, 2014
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2013-2139?

CVE-2013-2139 is classified as a high severity vulnerability due to its potential to cause denial of service through a buffer overflow.

2

How do I fix CVE-2013-2139?

To mitigate CVE-2013-2139, update libsrtp to version 1.4.6 or later, which addresses the buffer overflow issue.

3

What software is affected by CVE-2013-2139?

CVE-2013-2139 affects libsrtp versions up to and including 1.4.5, as well as various versions of Fedora and openSUSE.

4

Can CVE-2013-2139 be exploited remotely?

Yes, CVE-2013-2139 can be exploited remotely by attackers to trigger a denial of service.

5

What functions are involved in CVE-2013-2139?

The vulnerability in CVE-2013-2139 is related to the crypto_policy_set_from_profile_for_rtp and srtp_protect functions in libsrtp.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203