CVE-2022-21723: Out-of-bounds read in multipart parsing in PJSIP
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the master branch. There are no known workarounds.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-21723?
CVE-2022-21723 is a vulnerability in the PJSIP library that allows remote attackers to cause a denial of service (DoS) and potentially execute arbitrary code.
What is the severity of CVE-2022-21723?
CVE-2022-21723 has a severity rating of 9.1 (Critical).
Which software versions are affected by CVE-2022-21723?
Versions 2.11.1 and prior of Teluu Pjsip, Certified Asterisk 16.8.0, and Sangoma Asterisk 16.0.0 - 16.24.1, 18.0.0 - 18.10.1, and 19.0.0 - 19.2.1 are affected by CVE-2022-21723.
How can CVE-2022-21723 be exploited?
CVE-2022-21723 can be exploited by sending a malformed multipart SIP message, which can lead to out-of-bounds read/write access and potential code execution.
Is there a fix for CVE-2022-21723?
Yes, updating to the latest version of the affected software or applying the relevant patches provided by the vendors can fix CVE-2022-21723.