An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the potential to overflow, either causing unintended values to be captured or, if the values were subsequently converted back to strings, a buffer overrun. This will lead to a potential exploit using carefully crafted invalid values.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade pjproject | Apr 11, 2018 | Nov 17, 2017 |
| Ubuntu | — | Upgrade libpjmedia2 (Ubuntu Pro)Upgrade python-pjproject (Ubuntu Pro)Upgrade libpjnath2 (Ubuntu Pro)Upgrade libpjsua2 (Ubuntu Pro)Upgrade libpjsip2 (Ubuntu Pro)Upgrade libpj2 (Ubuntu Pro) | Jun 26, 2025 | Nov 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub