Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-16875

Опубликовано: 17 нояб. 2017
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. The ioqueue component may issue a double key unregistration after an attacker initiates a socket connection with specific settings and sequences. Such double key unregistration will trigger an integer overflow, which may cause ioqueue backends to reject future key registrations.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pjprojectfixed2.7.1~dfsg-1package
pjprojectignoredjessiepackage

Примечания

  • https://trac.pjsip.org/repos/ticket/2055

  • https://trac.pjsip.org/repos/changeset/5680

  • In jessie Asterisk doesn't use pjproject for SIP (only for ICE, STUN and TURN)

EPSS

Процентиль: 67%
0.00529
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. The ioqueue component may issue a double key unregistration after an attacker initiates a socket connection with specific settings and sequences. Such double key unregistration will trigger an integer overflow, which may cause ioqueue backends to reject future key registrations.

CVSS3: 7.5
nvd
около 8 лет назад

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. The ioqueue component may issue a double key unregistration after an attacker initiates a socket connection with specific settings and sequences. Such double key unregistration will trigger an integer overflow, which may cause ioqueue backends to reject future key registrations.

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. The ioqueue component may issue a double key unregistration after an attacker initiates a socket connection with specific settings and sequences. Such double key unregistration will trigger an integer overflow, which may cause ioqueue backends to reject future key registrations.

EPSS

Процентиль: 67%
0.00529
Низкий