Skip to content

Potential out-of-bound read/write when parsing RTCP FB RPSI

Low
sauwming published GHSA-vhxv-phmx-g52q Apr 6, 2022

Package

No package listed

Affected versions

2.12 or lower

Patched versions

2.12.1 or later

Description

Impact

Currently PJSIP doesn't parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected.

Patches

The patch is available as commit 11559e4 in the master branch.

For more information

If you have any questions or comments about this advisory:
Email us at security@pjsip.org

Severity

Low

CVE ID

CVE-2022-24786

Weaknesses

No CWEs

Credits