PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability that affects PJSUA2 users or users that call the API `pjmedia_sdp_print(), pjmedia_sdp_media_print()`. Applications that do not use PJSUA2 and do not directly call `pjmedia_sdp_print()` or `pjmedia_sdp_media_print()` should not be affected. A patch is available on the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pjproject | Mar 26, 2024 | Mar 22, 2022 |
| Debian | — | Upgrade ringUpgrade asterisk | Mar 29, 2022 | Mar 22, 2022 |
| Gentoo Linux | — | Upgrade net-libs/pjproject. | Nov 1, 2022 | Mar 22, 2022 |
| Ubuntu | — | Upgrade ring (Ubuntu Pro)Upgrade ring-daemonUpgrade ringUpgrade jamiUpgrade jami-daemonUpgrade ring-daemon (Ubuntu Pro) | Oct 10, 2023 | Mar 22, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub