V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-21722
DEB
Critical

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, S…

CVSS
9.1
Critical
EPSS
0.02
p81
Published
2022-01-01
Updated
2022-01-01
Description

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access. This issue affects all users that use PJMEDIA and accept incoming RTP/RTCP. A patch is available as a commit in the `master` branch. There are no known workarounds.

Tags · CWE
RCEPre-auth
CWE-125
CAPEC-540
Affected products
Debian_linux
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.024 · p81
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
asteriskTracked
asteriskTracked
pjprojectTracked
pjprojectTracked
pjprojectTracked
pjprojectTracked
ringTracked
ringTracked
ringTracked
ringTracked
ringTracked
ringTracked
ringTracked
ringTracked
debian_linux*Tracked
pjsip*Tracked
Source databases
DEB
CVE
UBU
Related vulnerabilities