CVE-2021-43845: Prevent out-of-bounds read in PJSIP
PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an out-of-bound read access. This affects all users that use PJMEDIA and RTCP XR. A malicious actor can send a RTCP XR message with an invalid packet size.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-43845?
CVE-2021-43845 is a vulnerability in the PJSIP multimedia communication library that allows for potential out-of-bound read access.
How does CVE-2021-43845 affect users?
CVE-2021-43845 affects all users that use PJMEDIA and have incoming RTCP XR messages with a block that is not checked against the received packet size.
What is the severity of CVE-2021-43845?
CVE-2021-43845 has a severity rating of 9.1 (critical).
How can I fix CVE-2021-43845?
To fix CVE-2021-43845, users should update to a version of PJSIP that includes the patch provided by the PJSIP project.
Where can I find more information about CVE-2021-43845?
More information about CVE-2021-43845 can be found in the references provided by the PJSIP project.