CVE-2021-43303
CRITICALPJSUA API - Buffer Overflow
Title source: llmDescription
Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 characters may overflow the output buffer, regardless of the 'maxlen' argument supplied
References (6)
Scores
CVSS v3
9.8
EPSS
0.0051
EPSS Percentile
66.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-120
Status
published
Affected Products (4)
teluu/pjsip
< 2.11.1
debian/debian_linux
debian/debian_linux
debian/debian_linux
Timeline
Published
Feb 16, 2022
Tracked Since
Feb 18, 2026