Skip to content

Heap buffer overflow when decoding STUN message (2)

Critical
sauwming published GHSA-cxwq-5g9x-x7fr Dec 23, 2022

Package

No package listed

Affected versions

2.13 or lower

Patched versions

2.13.1

Description

This is a continuation of GHSA-9pfh-r8x4-w26w.

Impact

Possible buffer overread when parsing a specially crafted STUN message. The vulnerability affects applications that uses STUN including PJNATH and PJSUA-LIB.

Patches

The patch is available as commit bc4812d in the master branch.

For more information

If you have any questions or comments about this advisory:
Email us at security@pjsip.org

Reporter

google/oss-fuzz

Severity

Critical

CVE ID

CVE-2022-23547

Weaknesses

No CWEs