Executive brief
The libbzrtp library, used to provide secure encrypted voice and video calls in applications like Linphone, contains a flaw in how it handles secure connection handshakes. An attacker positioned between two callers can exploit this to impersonate a user or intercept communications without being detected. This undermines the primary security feature intended to prevent eavesdropping on private conversations.
Technical details
A vulnerability exists in libbzrtp (Bzrtp) versions 1.0.x prior to 1.0.4 due to a missing Hash Value Indicator (HVI) check during the reception of DHPart2 packets in the ZRTP protocol. ZRTP uses a hash commitment mechanism to prevent Man-in-the-Middle (MiTM) attacks during ephemeral Diffie-Hellman key exchanges. By failing to validate the HVI against the commitment received in the earlier 'Commit' packet, the library allows an attacker to successfully negotiate keys with both endpoints. This enables a MiTM attacker to spoof identities or intercept media streams. The issue was addressed in version 1.0.4 by adding the necessary HVI validation logic.
Affected products
- Belledonne Communications libbzrtp 1.0.x before 1.0.4
Timeline
- 2016-07-19: patched: Fix committed to Belledonne Communications bzrtp repository
- 2017-01-18: disclosed: NVD publication date