Skip to content

Potential out-of-bound read during RTP/RTCP parsing

High
sauwming published GHSA-m66q-q64c-hv36 Jan 26, 2022

Package

No package listed

Affected versions

2.11.1 or lower

Patched versions

2.12 or later

Description

There are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access.

Impact

It affects all users that use PJMEDIA and accepts incoming RTP/RTCP.

Patches

The patch is available as commit 22af44e in the master branch.

For more information

If you have any questions or comments about this advisory:
Email us at security@pjsip.org

Severity

High

CVE ID

CVE-2022-21722

Weaknesses

No CWEs