Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-39269
HistoryOct 06, 2022 - 12:00 a.m.

CVE-2022-39269

2022-10-0600:00:00
ubuntu.com
ubuntu.com
20
pjsip
vulnerability
srtp
rtp
patch
upgrade
multimedia communication
library
c.

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

49.6%

PJSIP is a free and open source multimedia communication library written in
C. When processing certain packets, PJSIP may incorrectly switch from using
SRTP media transport to using basic RTP upon SRTP restart, causing the
media to be sent insecurely. The vulnerability impacts all PJSIP users that
use SRTP. The patch is available as commit d2acb9a in the master branch of
the project and will be included in version 2.13. Users are advised to
manually patch or to upgrade. There are no known workarounds for this
vulnerability.

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

49.6%