First published: Thu Mar 29 2018(Updated: )
The PJSIP PJSUA2 SDK before SVN Changeset 51322 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pjsip Pjsua2 Sdk | <51322 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2003 is a vulnerability in the PJSIP PJSUA2 SDK for Android that allows attackers to execute arbitrary code.
CVE-2015-2003 has a severity score of 9.8, which is considered critical.
CVE-2015-2003 allows attackers to execute arbitrary code by leveraging a finalize method in a Serializable class.
The CVE-2015-2003 vulnerability can be exploited by passing an attacker-controlled pointer to a native function.
Yes, updating to SVN Changeset 51322 or later of the PJSIP PJSUA2 SDK for Android fixes the CVE-2015-2003 vulnerability.