Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-27585

Опубликовано: 14 мар. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not utilise PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record parse_query(), while the issue in CVE-2022-24793 is in parse_rr(). A patch is available as commit d1c5e4d in the master branch. A workaround is to disable DNS resolution in PJSIP config (by setting nameserver_count to zero) or use an external resolver implementation instead.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:*
Версия до 2.13 (исключая)

EPSS

Процентиль: 62%
0.00436
Низкий

7.5 High

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not utilise PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue in CVE-2022-24793 is in `parse_rr()`. A patch is available as commit `d1c5e4d` in the `master` branch. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver implementation instead.

CVSS3: 7.5
debian
почти 3 года назад

PJSIP is a free and open source multimedia communication library writt ...

EPSS

Процентиль: 62%
0.00436
Низкий

7.5 High

CVSS3

Дефекты

CWE-120