First published: Wed Jun 11 2014(Updated: )
The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of service (assertion failure and abort) via an empty UDP packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PulseAudio | =1.0 | |
PulseAudio | =1.1 | |
PulseAudio | =1.99.1 | |
PulseAudio | =1.99.2 | |
PulseAudio | =2.0 | |
PulseAudio | =2.1 | |
PulseAudio | =3.0 | |
PulseAudio | =4.0 | |
PulseAudio | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3970 has a high severity due to its potential to cause a denial of service through an empty UDP packet.
The best way to fix CVE-2014-3970 is to upgrade to PulseAudio version 5.1 or later.
CVE-2014-3970 affects PulseAudio versions 5.0 and earlier.
CVE-2014-3970 can lead to assertion failures and cause PulseAudio services to abort when receiving an empty UDP packet.
An attacker on the same network can exploit CVE-2014-3970 by sending empty UDP packets to create a denial of service.