REDHAT-BUG-1323702: Medium severity cisco libsrtp vulnerability
Randell Jesup and the Firefox team discovered that srtp, Cisco's reference implementation of the Secure Real-time Transport Protocol (SRTP), does not properly handle RTP header CSRC count and extension header length. A remote attacker can exploit this vulnerability to crash an application linked against libsrtp, resulting in a denial of service.
References:
http://seclists.org/bugtraq/2016/Apr/11
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1323702?
The severity of REDHAT-BUG-1323702 is critical due to the potential for remote application crashes.
How do I fix REDHAT-BUG-1323702?
To fix REDHAT-BUG-1323702, you should apply the latest security patches for Cisco libsrtp.
Which versions of Cisco libsrtp are affected by REDHAT-BUG-1323702?
All versions of Cisco libsrtp that do not have the latest security updates are affected by REDHAT-BUG-1323702.
Can REDHAT-BUG-1323702 be exploited remotely?
Yes, a remote attacker can exploit REDHAT-BUG-1323702 to crash an application linked against the vulnerable libsrtp.
What is the impact of REDHAT-BUG-1323702 on applications?
The impact of REDHAT-BUG-1323702 is that it may lead to application instability and crashes when handling certain RTP header fields.