Vulnerabilities found in code library used by encrypted phone call apps

Vulnerabilities in the ZRTPCPP library affect several encrypted phone call apps, researchers said

ZRTPCPP, an open-source library that's used by several applications offering end-to-end encrypted phone calls, contained three vulnerabilities that could have enabled arbitrary code execution and denial-of-service attacks, according to researchers from security firm Azimuth Security.

ZRTPCPP is a C++ implementation of the ZRTP cryptographic key agreement protocol for VoIP (voice over IP) communications designed by PGP creator Phil Zimmermann.

The library is used by secure communications provider Silent Circle in its Silent Phone app, as well as by other programs that support encrypted phone calls, including CSipSimple, LinPhone, Twinkle, several client apps for the Ostel service and "anything using the GNU ccRTP with ZRTP enabled," said Azimuth Security co-founder Mark Dowd in a blog post on Thursday.

Following the recent reports about the U.S. National Security Agency's data collection programs that appear to cover Internet audio conversations, there's been an increased interest into encrypted communication services from end users.

The vulnerabilities in ZRTPCPP were found while evaluating the security of some of the products that offer encrypted phone call capabilities, Dowd said.

One vulnerability consists of a buffer overflow in the ZRtp::storeMsgTemp() function, the researcher said. "If an attacker sends a packet larger than 1024 bytes that gets stored temporarily (which occurs many times -- such as when sending a ZRTP Hello packet), a heap overflow will occur, leading to potential arbitrary code execution on the vulnerable host."

Another function, ZRtp::prepareCommit(), contains multiple stack overflows that occur when preparing a response to a client's ZRTP Hello packet. It is unlikely that this vulnerability is exploitable for remote code execution due to technical constraints, but it can be used to crash the target application, Dowd said.

The third vulnerability is an information leakage one and can be used to obtain information that could be used to achieve reliable remote code execution in conjunction with the previously mentioned heap overflow bug. "In addition, it could possibly be used to leak sensitive crypto-related data, although the extent of how useful this is has not been investigated," Dowd said.

In a later update to the blog post, Dowd said that patches for the vulnerabilities have been added to ZRTPCPP's code repository on Github and that Silent Circle has updated its own apps on Google Play and Apple's App Store with fixes.

This was only an initial analysis of a minor component of encrypted phone call apps, he said. "It would be beneficial for the security community to undertake further study of some of these products."

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags privacymobile securityonline safetypatchesExploits / vulnerabilitiesSilent CircleAzimuth Security

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.
Lucian Constantin

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Christopher Low

Brother RJ-4230B

This small mobile printer is exactly what I need for invoicing and other jobs such as sending fellow tradesman details or step-by-step instructions that I can easily print off from my phone or the Web.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?