VYPR
Unrated severityNVD Advisory· Published Oct 4, 2013· Updated Apr 29, 2026

CVE-2013-2223

CVE-2013-2223

Description

GNU ZRTPCPP before 3.2.0 allows remote attackers to obtain sensitive information (uninitialized heap memory) or cause a denial of service (out-of-bounds read) via a crafted packet, as demonstrated by a truncated Ping packet that is not properly handled by the getEpHash function.

Affected products

7
  • Wernerd/Zrtpcpp7 versions
    cpe:2.3:a:wernerd:zrtpcpp:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:wernerd:zrtpcpp:*:*:*:*:*:*:*:*range: <=3.2.1
    • cpe:2.3:a:wernerd:zrtpcpp:2.1.2:*:*:*:*:*:*:*
    • cpe:2.3:a:wernerd:zrtpcpp:2.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wernerd:zrtpcpp:2.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wernerd:zrtpcpp:3.0.0:alpha:*:*:*:*:*:*
    • cpe:2.3:a:wernerd:zrtpcpp:3.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:wernerd:zrtpcpp:3.2.0:*:*:*:*:*:*:*

Patches

1

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

8

News mentions

0

No linked articles in our index yet.