Input validation error in Wireshark - CVE-2014-2907
Published: April 24, 2014 / Updated: August 10, 2020
Wireshark
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.