CVE-2014-3970: Low severity Pulseaudio Pulseaudio vulnerability
Published Jun 11, 2014
·Updated
The partprecv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of service (assertion failure and abort) via an empty UDP packet.
Affected Software
9 affected components
Pulseaudio Pulseaudio=1.0
Pulseaudio Pulseaudio=1.1
Pulseaudio Pulseaudio=1.99.1
Pulseaudio Pulseaudio=1.99.2
Pulseaudio Pulseaudio=2.0
Pulseaudio Pulseaudio=2.1
Pulseaudio Pulseaudio=3.0
Pulseaudio Pulseaudio=4.0
Pulseaudio Pulseaudio=5.0
Event History
Jun 11, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3970?
CVE-2014-3970 has a high severity due to its potential to cause a denial of service through an empty UDP packet.
2
How do I fix CVE-2014-3970?
The best way to fix CVE-2014-3970 is to upgrade to PulseAudio version 5.1 or later.
3
Which versions of PulseAudio are affected by CVE-2014-3970?
CVE-2014-3970 affects PulseAudio versions 5.0 and earlier.
4
What is the impact of CVE-2014-3970 on PulseAudio services?
CVE-2014-3970 can lead to assertion failures and cause PulseAudio services to abort when receiving an empty UDP packet.
5
Who exploits CVE-2014-3970 in a network?
An attacker on the same network can exploit CVE-2014-3970 by sending empty UDP packets to create a denial of service.