Bug 881524 (CVE-2014-3970) - VUL-1: CVE-2014-3970: pulseaudio: denial of service in module-rtp-recv
Summary: VUL-1: CVE-2014-3970: pulseaudio: denial of service in module-rtp-recv
Status: RESOLVED FIXED
Alias: CVE-2014-3970
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Deadline: 2014-08-21
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/99318/
Whiteboard: maint:released:sle11-sp3:58409
Keywords:
Depends on:
Blocks:
 
Reported: 2014-06-05 12:03 UTC by Johannes Segitz
Modified: 2014-09-01 10:02 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-06-05 12:03:17 UTC
CVE-2014-3970

PulseAudio suffers from a remote denial of service if the module-rtp-recv module is loaded. A remote attacker could crash this instance of PulseAudio by sending an empty UDP packet to the multicast address that module-rtp-recv is listening

A potential patch has been submitted upstream but has not yet been accepted.
http://lists.freedesktop.org/archives/pulseaudio-discuss/2014-May/020741.html

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1104835
http://lists.freedesktop.org/archives/pulseaudio-discuss/2014-May/020740.html
http://openwall.com/lists/oss-security/2014/06/04/8
Comment 1 SMASH SMASH 2014-06-05 12:25:10 UTC
Affected packages:

SLE-11-SP3: pulseaudio
Comment 2 Swamp Workflow Management 2014-06-05 22:00:13 UTC
bugbot adjusting priority
Comment 3 Scott Reeves 2014-07-18 22:29:46 UTC
submitted. 

SUSE:SLE-11-SP2:Update:Test  - #41448
SUSE:SLE-12:GA - #41449
openSUSE_12.3 - #241566
openSUSE_13.1 - #241567
Comment 4 Swamp Workflow Management 2014-07-23 22:38:17 UTC
An update workflow for this issue was started.
This issue was rated as low.
Please submit fixed packages until 2014-08-21.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/58407
Comment 5 SMASH SMASH 2014-07-23 22:40:11 UTC
Affected packages:

SLE-11-SP2: pulseaudio
SLE-11-SP3: pulseaudio
Comment 6 Marcus Meissner 2014-07-29 08:10:05 UTC
we would also need a submission for 

SUSE:SLE-11-SP1:Update:Test pulseaudio
Comment 7 Scott Reeves 2014-08-06 23:40:00 UTC
added submission for SUSE:SLE-11-SP1:Update:Test - #42337
Comment 9 Swamp Workflow Management 2014-08-13 12:41:20 UTC
SUSE-SU-2014:1001-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 881524
CVE References: CVE-2014-3970
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Server 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
Comment 10 Swamp Workflow Management 2014-08-13 12:43:58 UTC
SUSE-SU-2014:0999-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 881524
CVE References: CVE-2014-3970
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Server 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
Comment 11 Swamp Workflow Management 2014-08-13 12:44:14 UTC
SUSE-SU-2014:1003-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 881524
CVE References: CVE-2014-3970
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Server 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
Comment 12 Swamp Workflow Management 2014-08-13 12:46:58 UTC
SUSE-SU-2014:1007-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 881524
CVE References: CVE-2014-3970
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Server 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
Comment 13 Swamp Workflow Management 2014-08-13 13:04:24 UTC
SUSE-SU-2014:1013-1: An update that fixes one vulnerability is now available.

Category: security (low)
Bug References: 881524
CVE References: CVE-2014-3970
Sources used:
SUSE Linux Enterprise Software Development Kit 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Server 11 SP3 for VMware (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Server 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
SUSE Linux Enterprise Desktop 11 SP3 (src):    pulseaudio-0.9.23-0.15.1
Comment 14 Marcus Meissner 2014-09-01 10:02:05 UTC
released