CVE-2015-2003: Critical severity pjsip pjsua2 sdk vulnerability
The PJSIP PJSUA2 SDK before SVN Changeset 51322 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-2003?
CVE-2015-2003 is a vulnerability in the PJSIP PJSUA2 SDK for Android that allows attackers to execute arbitrary code.
What is the severity of CVE-2015-2003?
CVE-2015-2003 has a severity score of 9.8, which is considered critical.
How does CVE-2015-2003 impact the PJSIP PJSUA2 SDK for Android?
CVE-2015-2003 allows attackers to execute arbitrary code by leveraging a finalize method in a Serializable class.
How can the CVE-2015-2003 vulnerability be exploited?
The CVE-2015-2003 vulnerability can be exploited by passing an attacker-controlled pointer to a native function.
Is there a fix available for CVE-2015-2003?
Yes, updating to SVN Changeset 51322 or later of the PJSIP PJSUA2 SDK for Android fixes the CVE-2015-2003 vulnerability.