PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known workarounds.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pjproject | Mar 26, 2024 | Mar 30, 2022 |
| Debian | — | Upgrade asteriskUpgrade ring | Jun 1, 2022 | Mar 30, 2022 |
| Gentoo Linux | — | Upgrade net-libs/pjproject. | Nov 1, 2022 | Mar 30, 2022 |
| Ubuntu | ubuntu-pro-upgrade-ringubuntu-pro-upgrade-ring-daemonubuntu-upgrade-jamiubuntu-upgrade-jami-daemonubuntu-upgrade-ringubuntu-upgrade-ring-daemon | Oct 10, 2023 | Mar 30, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub