VULNERABILITY INTELLIGENCE

CVE-2013-2139

CVSS score2.6 LOW
EPSS probability2.99%
CISA KEVNot currently listed
Published2014-01-16
Last modified2026-06-16
CVSS vectorAV:N/AC:H/Au:N/C:N/I:N/A:P

Description

Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and srtp_protect functions.

Weakness classification

  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

Primary references