Skip to content

Heap buffer overflow when decoding STUN message

Critical
sauwming published GHSA-9pfh-r8x4-w26w Dec 20, 2022

Package

No package listed

Affected versions

2.13 or lower

Patched versions

2.13.1

Description

Impact

Possible buffer overread when parsing a specially crafted STUN message with unknown attribute. The vulnerability affects applications that uses STUN including PJNATH and PJSUA-LIB.

Patches

The patch is available as commit d8440f4 in the master branch.

For more information

If you have any questions or comments about this advisory:
Email us at security@pjsip.org

Reporter

google/oss-fuzz

Severity

Critical

CVE ID

CVE-2022-23537

Weaknesses

No CWEs