CVE-2021-43303

CRITICAL

PJSUA API - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 characters may overflow the output buffer, regardless of the 'maxlen' argument supplied

Scores

CVSS v3 9.8
EPSS 0.0041
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (4)
debian/debian_linux 9.0
debian/debian_linux 10.0
debian/debian_linux 11.0
teluu/pjsip < 2.11.1
Published Feb 16, 2022
Tracked Since Feb 18, 2026