Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-23537
HistoryDec 20, 2022 - 6:50 p.m.

CVE-2022-23537 PJSIP vulnerable to heap buffer overflow when decoding STUN message

2022-12-2018:50:45
CWE-122
GitHub_M
www.cve.org
5
pjsip
heap buffer overflow
cve-2022-23537
stun message
patch available
multimedia library
sip
sdp
rtp
stun
turn
ice
buffer overread
pjnath
pjsua-lib
commit
master branch

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

57.2%

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted STUN message with unknown attribute. The vulnerability affects applications that uses STUN including PJNATH and PJSUA-LIB. The patch is available as a commit in the master branch (2.13.1).

CNA Affected

[
  {
    "vendor": "pjsip",
    "product": "pjproject",
    "versions": [
      {
        "version": "<= 2.13",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

57.2%