CVE-2021-43299: Buffer Overflow
Published Feb 16, 2022
·Updated
Stack overflow in PJSUA API when calling pjsuaplayercreate. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.
Affected Software
8 affected componentsFixes available
debian/asterisk
1:16.28.0~dfsg-0+deb10u41:16.28.0~dfsg-0+deb11u31:16.28.0~dfsg-0+deb11u41:20.6.0~dfsg+~cs6.13.40431414-2
debian/ring<=20190215.1.f152c98~ds1-1+deb10u1, <=20210112.2.b757bac~ds1-1
20190215.1.f152c98~ds1-1+deb10u220230206.0~ds2-1.120231201.0~ds1-1
ubuntu/ring<20180228.1.503
20180228.1.503
ubuntu/ring<20190215.1.
20190215.1.
Teluu PJSIP<=2.11.1
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
Feb 16, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:01 AM
Description
Frequently Asked Questions
1
What is CVE-2021-43299?
CVE-2021-43299 is a vulnerability that allows a stack overflow in PJSUA API when calling pjsua_player_create.
2
What is the severity of CVE-2021-43299?
CVE-2021-43299 has a severity rating of 9.8 (Critical).
3
Which software is affected by CVE-2021-43299?
CVE-2021-43299 affects Teluu Pjsip versions up to and including 2.11.1, as well as Debian Linux versions 9.0, 10.0, and 11.0.
4
How does CVE-2021-43299 occur?
CVE-2021-43299 occurs when an attacker-controlled 'filename' argument is passed to pjsua_player_create, causing a buffer overflow.
5
How can I fix CVE-2021-43299?
To fix CVE-2021-43299, update to the latest version of Teluu Pjsip or Debian Linux, depending on the affected software.