CVE-2022-21722

Name
CVE-2022-21722
Description
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access. This issue affects all users that use PJMEDIA and accept incoming RTP/RTCP. A patch is available as a commit in the `master` branch. There are no known workarounds.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/pjsip/pjproject/security/advisories/GHSA-m66q-q64c-hv36
MISC https://github.com/pjsip/pjproject/commit/22af44e68a0c7d190ac1e25075e1382f77e9397a
mailing-list https://lists.debian.org/debian-lts-announce/2022/03/msg00035.html
vendor-advisory https://security.gentoo.org/glsa/202210-37
mailing-list https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html
vendor-advisory https://www.debian.org/security/2022/dsa-5285
mailing-list https://lists.debian.org/debian-lts-announce/2023/08/msg00038.html
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2024/09/msg00030.html

Match rules

CPE URI Source package Min version Max version
pjproject >= 0 <= 2.11.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
pjproject edge-main 2.12-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
pjproject edge-main 2.11.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
pjproject edge-main 2.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
pjproject 3.22-main 2.12-r0 None fixed
pjproject 3.22-main 2.11.1-r0 None possibly vulnerable
pjproject 3.22-main 2.11-r0 None possibly vulnerable
pjproject 3.21-main 2.12-r0 None fixed
pjproject 3.21-main 2.11.1-r0 None possibly vulnerable
pjproject 3.21-main 2.11-r0 None possibly vulnerable
pjproject 3.20-main 2.12-r0 None fixed
pjproject 3.20-main 2.11.1-r0 None possibly vulnerable
pjproject 3.20-main 2.11-r0 None possibly vulnerable
pjproject 3.19-main 2.12-r0 None fixed
pjproject 3.19-main 2.11.1-r0 None possibly vulnerable
pjproject 3.19-main 2.11-r0 None possibly vulnerable
pjproject 3.18-main 2.12-r0 None fixed
pjproject 3.17-main 2.12-r0 None fixed