{"id":"UBUNTU-CVE-2013-2223","details":"GNU ZRTPCPP before 3.2.0 allows remote attackers to obtain sensitive information (uninitialized heap memory) or cause a denial of service (out-of-bounds read) via a crafted packet, as demonstrated by a truncated Ping packet that is not properly handled by the getEpHash function.","modified":"2025-07-16T07:17:06.680733Z","published":"2013-10-04T17:55:00Z","withdrawn":"2025-07-18T16:42:51Z","upstream":["CVE-2013-2223"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2013-2223"},{"type":"REPORT","url":"http://blog.azimuthsecurity.com/2013/06/attacking-crypto-phones-weaknesses-in.html"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2013-2223"}],"affected":[{"package":{"name":"libzrtpcpp","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/libzrtpcpp@2.3.4-1.1?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.4-1.1"}]}],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"2.3.4-1.1","binary_name":"libzrtpcpp-dev"},{"binary_name":"libzrtpcpp2","binary_version":"2.3.4-1.1"},{"binary_version":"2.3.4-1.1","binary_name":"libzrtpcpp2-dbgsym"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-2223.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}