CVE-2022-24754Classic Buffer Overflow in Pjproject

Severity
9.8CRITICALNVD
EPSS
0.5%
top 35.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11
Latest updateOct 24

Description

PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and including 2.12 PJSIP there is a stack-buffer overflow vulnerability which only impacts PJSIP users who accept hashed digest credentials (credentials with data_type `PJSIP_CRED_DATA_DIGEST`). This issue has been patched in the master branch of the PJSIP repository and will be included with the next release. Users unable to upgrade need to check that the hashed digest data length must b

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDteluu/pjsip2.12
CVEListV5pjsip/pjproject2.12
debiandebian/ring< ring 20230206.0~ds1-1 (bookworm)
debiandebian/asterisk< ring 20230206.0~ds1-1 (bookworm)

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

3
OSV
ring vulnerabilities2023-10-24
OSV
ring vulnerabilities2023-10-09
OSV
CVE-2022-24754: PJSIP is a free and open source multimedia communication library written in C language2022-03-11

📋Vendor Advisories

3
Ubuntu
Ring vulnerabilities2023-10-24
Ubuntu
Ring vulnerabilities2023-10-09
Debian
CVE-2022-24754: asterisk - PJSIP is a free and open source multimedia communication library written in C la...2022

💬Community

2
Bugzilla
CVE-2021-438450 CVE-2021-438451 CVE-2022-217221 CVE-2022-247541 CVE-2022-247542 CVE-2022-247631 CVE-2022-247633 CVE-2022-247641 CVE-2022-247644 CVE-2022-247931 CVE-2022-247935 asterisk: pjsip: Multipl2023-02-27
Bugzilla
CVE-2021-41141 CVE-2021-43845 CVE-2022-24754 CVE-2022-24763 CVE-2022-24786 CVE-2022-24792 CVE-2022-24793 asterisk: pjsip: Multiple vulnerabilities [epel-all]2023-02-27
CVE-2022-24754 — Classic Buffer Overflow in Pjproject | cvebase