PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an out-of-bound read access. This affects all users that use PJMEDIA and RTCP XR. A malicious actor can send a RTCP XR message with an invalid packet size.
References
Configurations
History
21 Nov 2024, 06:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/pjsip/pjproject/commit/f74c1fc22b760d2a24369aa72c74c4a9ab985859 - Patch, Third Party Advisory | |
References | () https://github.com/pjsip/pjproject/pull/2924 - Exploit, Issue Tracking, Patch, Third Party Advisory | |
References | () https://github.com/pjsip/pjproject/security/advisories/GHSA-r374-qrwv-86hh - Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2022/03/msg00035.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/08/msg00038.html - | |
References | () https://security.gentoo.org/glsa/202210-37 - Third Party Advisory | |
References | () https://www.debian.org/security/2022/dsa-5285 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 6.4
v3 : 8.2 |
30 Aug 2023, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2021-12-27 18:15
Updated : 2024-11-21 06:29
NVD link : CVE-2021-43845
Mitre link : CVE-2021-43845
CVE.ORG link : CVE-2021-43845
JSON object : View
Products Affected
teluu
- pjsip
debian
- debian_linux
CWE
CWE-125
Out-of-bounds Read