CVE-2014-2907
EPSS 0.21%Published: 4/24/2014Modified: 4/28/2026
Description
The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
Affected packages (1)
- Debian/wiresharkfrom 0, < 1.10.7-1