LWN.net Logo

libzrtpcpp: multiple vulnerabilities

Package(s):libzrtpcpp CVE #(s):CVE-2013-2221 CVE-2013-2222 CVE-2013-2223
Created:July 16, 2013 Updated:September 25, 2013
Description: From the Red Hat bugzilla [1, 2, 3]:

A heap-based buffer overflow flaw was found in the way libzrtpcpp, a ZRTP support library for the GNU ccRTP stack, processed certain ZRTP packets (overly-large ZRTP packets of several types). A remote attacker could provide a specially-crafted ZRTP packet that, when processed in an application linked against libzrtpcpp would lead to that application crash or, potentially, arbitrary code execution with the privileges of the user running that application. (CVE-2013-2221)

Multiple stack-based buffer overflows were found in the way libzrtpcpp, a ZRTP support library for the GNU ccRTP stack, processed certain ZRTP Hello packets (ZRTP Hello packets with an overly-large value in certain fields, including the count of public keys). A remote attacker could provide a specially-crafted ZRTP packet that, when processed in an application linked against libzrtpcpp would lead to that application crash. (CVE-2013-2222)

Multiple information (heap memory content) exposure flaws were found in the way libzrtpcpp, a ZRTP support library for the GNU ccRTP stack, processed truncated ZRTP Ping packets. A remote attacker could provide a specially-crafted ZRTP Ping packet that, when processed in an application linked against libzrtpcpp would potentially reveal sensitive information stored on the heap. (CVE-2013-2223)

Alerts:
Fedora FEDORA-2013-12479 2013-07-16
Fedora FEDORA-2013-13019 2013-07-24
Fedora FEDORA-2013-13018 2013-07-24
Fedora FEDORA-2013-13019 2013-07-24
Fedora FEDORA-2013-13018 2013-07-24
Fedora FEDORA-2013-13019 2013-07-24
Fedora FEDORA-2013-13018 2013-07-24
Gentoo 201309-13 2013-09-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds