Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-24763

Опубликовано: 30 мар. 2022
Источник: debian
EPSS Низкий

Описание

PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known workarounds.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
asteriskfixed1:18.14.0~~rc1~dfsg+~cs6.12.40431414-1package
asterisknot-affectedstretchpackage
pjprojectremovedpackage
ringfixed20230206.0~ds1-1package

Примечания

  • https://github.com/pjsip/pjproject/security/advisories/GHSA-5x45-qp78-g4p4

  • https://github.com/pjsip/pjproject/commit/856f87c2e97a27b256482dbe0d748b1194355a21

EPSS

Процентиль: 49%
0.00256
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known workarounds.

CVSS3: 7.5
nvd
около 3 лет назад

PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known workarounds.

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость мультимедийной коммуникационной библиотеки PJSIP, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании

redos
около 3 лет назад

Множественные уязвимости pjproject

EPSS

Процентиль: 49%
0.00256
Низкий