CVE-2022-23537: PJSIP vulnerable to heap buffer overflow when decoding STUN message
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted STUN message with unknown attribute. The vulnerability affects applications that uses STUN including PJNATH and PJSUA-LIB. The patch is available as a commit in the master branch (2.13.1).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-23537?
CVE-2022-23537 is a vulnerability in the PJSIP library that allows buffer overread when parsing a specially crafted STUN message with unknown attribute.
Which software is affected by CVE-2022-23537?
Teluu Pjsip version up to 2.13.1, Asterisk version up to 1:16.28.0~dfsg-0+deb10u3, 1:16.28.0~dfsg-0+deb11u2, 1:16.28.0~dfsg-0+deb11u3, and 1:20.4.0~dfsg+~cs6.13.40431414-2, and Ring version up to 20190215.1.f152c98~ds1-1+deb10u2, 20230206.0~ds2-1.1, and 20230206.0~ds2-1.3 are affected by CVE-2022-23537.
What is the severity of CVE-2022-23537?
CVE-2022-23537 has a severity rating of 9.8 (Critical).
How can I fix CVE-2022-23537 in Teluu Pjsip?
To fix CVE-2022-23537 in Teluu Pjsip, update to version 2.13.2 or later.
How can I fix CVE-2022-23537 in Asterisk?
To fix CVE-2022-23537 in Asterisk, update to version 1:16.2.1~dfsg-1+deb10u2 or later, 1:16.28.0~dfsg-0+deb11u2 or later, 1:16.28.0~dfsg-0+deb11u3 or later, or 1:20.4.0~dfsg+~cs6.13.40431414-3 or later.
How can I fix CVE-2022-23537 in Ring?
To fix CVE-2022-23537 in Ring, update to version 20190215.1.f152c98~ds1-1+deb10u3 or later, 20230206.0~ds2-1.2 or later, or 20230206.0~ds2-1.4 or later.