Mandriva Linux Security Advisory : srtp (MDVSA-2014:219)
Low Nessus Plugin ID 79406
SynopsisThe remote Mandriva Linux host is missing a security update.
DescriptionUpdated srtp package fixes security vulnerability :
Fernando Russ from Groundworks Technologies reported a buffer overflow flaw in srtp, Cisco's reference implementation of the Secure Real-time Transport Protocol (SRTP), in how the crypto_policy_set_from_profile_for_rtp() function applies cryptographic profiles to an srtp_policy. A remote attacker could exploit this vulnerability to crash an application linked against libsrtp, resulting in a denial of service (CVE-2013-2139).
SolutionUpdate the affected srtp package.