CVE-2021-43300: Buffer Overflow
Stack overflow in PJSUA API when calling pjsuarecordercreate. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-43300?
CVE-2021-43300 is a vulnerability in the PJSUA API that allows a stack overflow when calling pjsua_recorder_create, potentially leading to a buffer overflow.
Which software is affected by CVE-2021-43300?
Teluu Pjsip version up to and including 2.11.1, Debian Linux versions 9.0, 10.0, and 11.0, and the Ring package versions 20180228.1.503 and 20190215.1.
What is the severity of CVE-2021-43300?
The severity of CVE-2021-43300 is critical with a CVSS score of 9.8.
How can I fix CVE-2021-43300 for Teluu Pjsip?
Update Teluu Pjsip to version 2.11.2 or newer to fix CVE-2021-43300.
How can I fix CVE-2021-43300 for Debian Linux?
Update your Debian Linux distribution to the latest LTS version and apply the necessary security updates to fix CVE-2021-43300.
How can I fix CVE-2021-43300 for the Ring package?
Update the Ring package to the latest version available that includes the fix for CVE-2021-43300.