The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of service (assertion failure and abort) via an empty UDP packet. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3970