CVE-2013-2223
04.10.2013, 17:55
GNU ZRTPCPP before 3.2.0 allows remote attackers to obtain sensitive information (uninitialized heap memory) or cause a denial of service (out-of-bounds read) via a crafted packet, as demonstrated by a truncated Ping packet that is not properly handled by the getEpHash function.Enginsight
| Vendor | Product | Version |
|---|---|---|
| wernerd | zrtpcpp | 𝑥 ≤ 3.2.1 |
| wernerd | zrtpcpp | 2.1.2 |
| wernerd | zrtpcpp | 2.2.0 |
| wernerd | zrtpcpp | 2.3.0 |
| wernerd | zrtpcpp | 3.0.0:alpha |
| wernerd | zrtpcpp | 3.1.0 |
| wernerd | zrtpcpp | 3.2.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References