CVE-2014-3970

low
Published 2014-06-11 · Modified 2026-05-06
CVSS v3
CVSS v2
2.9
VIR risk
2.9

Description

The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of service (assertion failure and abort) via an empty UDP packet.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-3970

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed5.0-3
debian debianbullseyefixed5.0-3
debian debianforkyfixed5.0-3
debian debiansidfixed5.0-3
debian debiantrixiefixed5.0-3

Application impact

VendorProductVersionsFixed
pulseaudiopulseaudio1.0
pulseaudiopulseaudio1.1
pulseaudiopulseaudio1.99.1
pulseaudiopulseaudio1.99.2
pulseaudiopulseaudio2.0
pulseaudiopulseaudio2.1
pulseaudiopulseaudio3.0
pulseaudiopulseaudio4.0
pulseaudiopulseaudio5.0

References

Verify integrity in audit chain (admin only). AS-IS.