Required CVE Record Information
Description
PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV files. The vulnerability occurs when reading WAV file data chunks with length greater than 31-bit integers. The vulnerability does not affect 64-bit apps and should not affect apps that only plays trusted WAV files. A patch is available on the `master` branch of the `pjsip/project` GitHub repository. As a workaround, apps can reject a WAV file received from an unknown source or validate the file first.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
7.5 | HIGH | 3.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References 6 Total
- https://github.com/pjsip/pjproject/security/advisories/GHSA-rwgw-vwxg-q799
- https://github.com/pjsip/pjproject/commit/947bc1ee6d05be10204b918df75a503415fd3213
- lists.debian.org: [debian-lts-announce] 20220531 [SECURITY] [DLA 3036-1] pjproject security update mailing-list
- security.gentoo.org: GLSA-202210-37 vendor-advisory
- lists.debian.org: [debian-lts-announce] 20221117 [SECURITY] [DLA 3194-1] asterisk security update mailing-list
- debian.org: DSA-5285 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 6 Total
- https://github.com/pjsip/pjproject/security/advisories/GHSA-rwgw-vwxg-q799 x_transferred
- https://github.com/pjsip/pjproject/commit/947bc1ee6d05be10204b918df75a503415fd3213 x_transferred
- lists.debian.org: [debian-lts-announce] 20220531 [SECURITY] [DLA 3036-1] pjproject security update mailing-listx_transferred
- security.gentoo.org: GLSA-202210-37 vendor-advisoryx_transferred
- lists.debian.org: [debian-lts-announce] 20221117 [SECURITY] [DLA 3194-1] asterisk security update mailing-listx_transferred
- debian.org: DSA-5285 vendor-advisoryx_transferred