GLSA-201405-02 : libSRTP: Denial of Service
Low Nessus Plugin ID 73858
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-201405-02 (libSRTP: Denial of Service)
A flaw was found in how the crypto_policy_set_from_profile_for_rtp() function applies cryptographic profiles to an srtp_policy in libSRTP.
A remote attacker could exploit this vulnerability to crash an application linked against libSRTP, resulting in Denial of Service.
There is no known workaround at this time.
SolutionAll libSRTP users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-libs/libsrtp-1.4.4_p20121108-r1'