Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-37706
HistoryDec 22, 2021 - 12:00 a.m.

CVE-2021-37706

2021-12-2200:00:00
ubuntu.com
ubuntu.com
20
pjsip
remote code execution
udp
stun
integer underflow

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.022

Percentile

89.6%

PJSIP is a free and open source multimedia communication library written in
C language implementing standard based protocols such as SIP, SDP, RTP,
STUN, TURN, and ICE. In affected versions if the incoming STUN message
contains an ERROR-CODE attribute, the header length is not checked before
performing a subtraction operation, potentially resulting in an integer
underflow scenario. This issue affects all users that use STUN. A malicious
actor located within the victim’s network may forge and send a specially
crafted UDP (STUN) message that could remotely execute arbitrary code on
the victim’s machine. Users are advised to upgrade as soon as possible.
There are no known workarounds.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchpjproject<Β anyUNKNOWN
ubuntu16.04noarchpjproject<Β anyUNKNOWN
ubuntu18.04noarchring<Β 20180228.1.503da2b~ds1-1ubuntu0.1~esm1UNKNOWN
ubuntu20.04noarchring<Β 20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1UNKNOWN
ubuntu23.04noarchring<Β 20230206.0~ds1-5ubuntu0.1UNKNOWN
ubuntu23.10noarchring<Β 20230206.0~ds2-1.3ubuntu0.1UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.022

Percentile

89.6%