CVE-2021-43303

CRITICAL

PJSUA API - Buffer Overflow

Title source: llm

Description

Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 characters may overflow the output buffer, regardless of the 'maxlen' argument supplied

Scores

CVSS v3 9.8
EPSS 0.0051
EPSS Percentile 66.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-120
Status published

Affected Products (4)

teluu/pjsip < 2.11.1
debian/debian_linux
debian/debian_linux
debian/debian_linux

Timeline

Published Feb 16, 2022
Tracked Since Feb 18, 2026