PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions prior to and including 2.12.1 a stack buffer overflow vulnerability affects PJSIP users that use STUN in their applications, either by: setting a STUN server in their account/media config in PJSUA/PJSUA2 level, or directly using `pjlib-util/stun_simple` API. A patch is available in commit 450baca which should be included in the next release. There are no known workarounds for this issue.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade pjproject | Aug 22, 2024 | Jun 7, 2022 |
| Debian | — | Upgrade asteriskUpgrade ring | Feb 24, 2023 | Jun 9, 2022 |
| Gentoo Linux | — | Upgrade net-libs/pjproject. | Nov 1, 2022 | Jun 9, 2022 |
| Ubuntu | — | Upgrade ringUpgrade jami-daemonUpgrade jamiUpgrade ring (Ubuntu Pro)Upgrade ring-daemon (Ubuntu Pro)Upgrade ring-daemon | Oct 10, 2023 | Jun 9, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub