Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-23547
HistoryDec 23, 2022 - 12:00 a.m.

CVE-2022-23547

2022-12-2300:00:00
ubuntu.com
ubuntu.com
18
pjsip
multimedia communication
buffer overread
stun
rtp
ice
vulnerability
patch
unix
commit
master branch

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.9%

PJSIP is a free and open source multimedia communication library written in
C language implementing standard based protocols such as SIP, SDP, RTP,
STUN, TURN, and ICE. This issue is similar to GHSA-9pfh-r8x4-w26w. Possible
buffer overread when parsing a certain STUN message. The vulnerability
affects applications that uses STUN including PJNATH and PJSUA-LIB. The
patch is available as commit in the master branch.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchpjproject< anyUNKNOWN
ubuntu16.04noarchpjproject< anyUNKNOWN
ubuntu18.04noarchring< 20180228.1.503da2b~ds1-1ubuntu0.1~esm1UNKNOWN
ubuntu20.04noarchring< 20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1UNKNOWN

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.9%