Bug 2050387 (CVE-2022-21723) - CVE-2022-21723 pjsip: malformed SIP packets may cause out-of-bounds read access
Summary: CVE-2022-21723 pjsip: malformed SIP packets may cause out-of-bounds read access
Keywords:
Status: CLOSED UPSTREAM
Alias: CVE-2022-21723
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2050388 2050389
Blocks: 2050379
TreeView+ depends on / blocked
 
Reported: 2022-02-03 20:31 UTC by Anten Skrabec
Modified: 2022-02-03 21:13 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: ---
Doc Text:
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the `master` branch. There are no known workarounds.
Clone Of:
Environment:
Last Closed: 2022-02-03 21:13:52 UTC
Embargoed:


Attachments (Terms of Use)

Description Anten Skrabec 2022-02-03 20:31:16 UTC
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the `master` branch. There are no known workarounds.

https://github.com/pjsip/pjproject/security/advisories/GHSA-7fw8-54cv-r7pm
https://github.com/pjsip/pjproject/commit/077b465c33f0aec05a49cd2ca456f9a1b112e896

Comment 1 Anten Skrabec 2022-02-03 20:31:36 UTC
Created pjproject tracking bugs for this issue:

Affects: epel-all [bug 2050388]
Affects: fedora-all [bug 2050389]

Comment 2 Product Security DevOps Team 2022-02-03 21:13:50 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.


Note You need to log in before you can comment on or make changes to this bug.