V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-37706
DEB
Critical

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, S…

CVSS
9.8
Critical
EPSS
0.05
p90
Published
2021-01-01
Updated
2021-01-01
Description

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not checked before performing a subtraction operation, potentially resulting in an integer underflow scenario. This issue affects all users that use STUN. A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s machine. Users are advised to upgrade as soon as possible. There are no known workarounds.

Tags · CWE
Pre-auth
CWE-191
Affected products
Certified_asterisk < 16.8.0Certified_asteriskAsterisk 16.0.0–16.24.1Asterisk 18.0.0–18.10.1Asterisk 19.0.0–19.2.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.046 · p90
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
asteriskTracked
asteriskTracked
pjprojectTracked
pjprojectTracked
pjprojectTracked
pjprojectTracked
ringTracked
ringTracked
ringTracked
ringTracked
ringTracked
ringTracked
ringTracked
ringTracked
asterisk*Tracked
certified_asterisk*Tracked
debian_linux*Tracked
pjsip*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities