CVE-2022-23547: Heap buffer overflow in pjproject when decoding STUN message
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. This issue is similar to GHSA-9pfh-r8x4-w26w. Possible buffer overread when parsing a certain STUN message. The vulnerability affects applications that uses STUN including PJNATH and PJSUA-LIB. The patch is available as commit in the master branch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-23547?
CVE-2022-23547 is a vulnerability in the PJSIP multimedia communication library that allows for possible buffer overread when parsing a certain STUN message.
How does CVE-2022-23547 impact PJSIP and Ubuntu Ring?
CVE-2022-23547 affects PJSIP versions up to 2.13.1, as well as Ubuntu Ring versions 20180228.1.503 and 20190215.1.
What is the severity of CVE-2022-23547?
CVE-2022-23547 has a severity rating of 9.8 (critical).
How do I fix CVE-2022-23547 in PJSIP?
To fix CVE-2022-23547 in PJSIP, upgrade to a version higher than 2.13.1.
How do I fix CVE-2022-23547 in Ubuntu Ring?
To fix CVE-2022-23547 in Ubuntu Ring, update to a version higher than 20180228.1.503 or 20190215.1, depending on the specific package.