Description
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access. This issue affects all users that use PJMEDIA and accept incoming RTP/RTCP. A patch is available as a commit in the `master` branch. There are no known workarounds.
References (8)
Core 8
Core References
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/03/msg00035.html
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202210-37
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html
Third Party Advisory vendor-advisory
https://www.debian.org/security/2022/dsa-5285
Mailing List mailing-list
https://lists.debian.org/debian-lts-announce/2023/08/msg00038.html
Patch, Third Party Advisory
https://github.com/pjsip/pjproject/commit/22af44e68a0c7d190ac1e25075e1382f77e9397a
Patch, Third Party Advisory
https://github.com/pjsip/pjproject/security/advisories/GHSA-m66q-q64c-hv36
Scores
CVSS v3
9.1
EPSS
0.0046
EPSS Percentile
64.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (3)
debian/debian_linux
9.0
debian/debian_linux
10.0
teluu/pjsip
< 2.11.1
Published
Jan 27, 2022
Tracked Since
Feb 18, 2026