Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41415

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 7.5

Описание

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient length validation can cause reads beyond the intended buffer bounds. This vulnerability is fixed in 2.17.

A flaw was found in PJSIP, a multimedia communication library. A remote attacker could exploit this vulnerability by sending a specially crafted Session Initiation Protocol (SIP) multipart message containing a malformed Content-ID URI. Insufficient length validation during parsing of this URI can lead to an out-of-bounds read, potentially causing a denial of service.

Отчет

This is an Important denial of service flaw in PJSIP, a multimedia communication library. A remote attacker can trigger an out-of-bounds read by sending a specially crafted SIP multipart message with a malformed Content-ID URI, leading to service unavailability. This vulnerability affects Red Hat Community Projects that utilize PJSIP, such as pjproject and asterisk.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2461641pjproject: PJSIP: Denial of service via malformed Content-ID URI in SIP multipart message

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
4 месяца назад

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient length validation can cause reads beyond the intended buffer bounds. This vulnerability is fixed in 2.17.

CVSS3: 9.1
nvd
4 месяца назад

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, there is an out-of-bounds read when parsing a malformed Content-ID URI in SIP multipart message body. Insufficient length validation can cause reads beyond the intended buffer bounds. This vulnerability is fixed in 2.17.

CVSS3: 9.1
debian
4 месяца назад

PJSIP is a free and open source multimedia communication library writt ...

7.5 High

CVSS3