CVE-2022-21723
Out-of-bounds read in multipart parsing in PJSIP
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the `master` branch. There are no known workarounds.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected products
pjsip · pjprojectpublic PoCs found — 1
cve_referencepacketstormsecurity.com/files/166227/Asterisk-Project-Security-Advisory-AST-2022-006.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/166227/Asterisk-Project-Security-Advisory-AST-2022-006.htmlhttp://seclists.org/fulldisclosure/2022/Mar/2https://github.com/pjsip/pjproject/commit/077b465c33f0aec05a49cd2ca456f9a1b112e896https://github.com/pjsip/pjproject/security/advisories/GHSA-7fw8-54cv-r7pmhttps://lists.debian.org/debian-lts-announce/2022/03/msg00035.htmlhttps://lists.debian.org/debian-lts-announce/2022/11/msg00021.htmlhttps://lists.debian.org/debian-lts-announce/2023/08/msg00038.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00030.htmlhttps://security.gentoo.org/glsa/202210-37https://www.debian.org/security/2022/dsa-5285