Skip to content

Potential stack buffer overflow when printing SDP into a buffer

Critical
sauwming published GHSA-f5qg-pqcg-765m Mar 22, 2022

Package

No package listed

Affected versions

2.12 or lower

Patched versions

2.12.1 or later

Description

Impact

It is a stack buffer overflow vulnerability and affects PJSUA2 users or users that directly calls the API pjmedia_sdp_print(), pjmedia_sdp_media_print(). Applications that do not use PJSUA2 and do not directly call pjmedia_sdp_print() or pjmedia_sdp_media_print() should not be affected.

Patches

The patch is available as commit 560a134 in the master branch.

For more information

If you have any questions or comments about this advisory:
Email us at security@pjsip.org

Severity

Critical

CVE ID

CVE-2022-24764

Weaknesses

No CWEs

Credits