Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-37706

Опубликовано: 22 дек. 2021
Источник: debian
EPSS Низкий

Описание

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not checked before performing a subtraction operation, potentially resulting in an integer underflow scenario. This issue affects all users that use STUN. A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s machine. Users are advised to upgrade as soon as possible. There are no known workarounds.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
asteriskfixed1:18.10.1~dfsg+~cs6.10.40431411-1package
asterisknot-affectedstretchpackage
pjprojectremovedpackage
ringfixed20230206.0~ds1-1package

Примечания

  • https://issues.asterisk.org/jira/browse/ASTERISK-29945

  • https://downloads.asterisk.org/pub/security/AST-2022-004.html

  • https://github.com/pjsip/pjproject/security/advisories/GHSA-2qpg-f6wf-w984

  • Fixed by: https://github.com/pjsip/pjproject/commit/15663e3f37091069b8c98a7fce680dc04bc8e865

  • Superseeded by: https://github.com/savoirfairelinux/pjproject/commit/4cea72a4db91c6f0a0984b82edf2f147eda289aa

EPSS

Процентиль: 47%
0.00244
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 4 лет назад

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not checked before performing a subtraction operation, potentially resulting in an integer underflow scenario. This issue affects all users that use STUN. A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s machine. Users are advised to upgrade as soon as possible. There are no known workarounds.

CVSS3: 7.3
nvd
около 4 лет назад

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not checked before performing a subtraction operation, potentially resulting in an integer underflow scenario. This issue affects all users that use STUN. A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s machine. Users are advised to upgrade as soon as possible. There are no known workarounds.

CVSS3: 7.3
fstec
больше 4 лет назад

Уязвимость мультимедийной коммуникационной библиотеки PJSIP, связанная с целочисленной потерей значимости, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 47%
0.00244
Низкий