CVE-2022-24763: Infinite Loop in PJSIP
Published Mar 30, 2022
·Updated
PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known workarounds.
Affected Software
9 affected componentsFixes available
debian/asterisk
1:16.28.0~dfsg-0+deb10u41:16.28.0~dfsg-0+deb11u31:16.28.0~dfsg-0+deb11u41:20.6.0~dfsg+~cs6.13.40431414-2
debian/ring<=20190215.1.f152c98~ds1-1+deb10u1, <=20210112.2.b757bac~ds1-1
20190215.1.f152c98~ds1-1+deb10u220230206.0~ds2-1.120231201.0~ds1-1
ubuntu/ring<20180228.1.503
20180228.1.503
ubuntu/ring<20190215.1.
20190215.1.
PJSIP PJSIP<=2.12
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Teluu PJSIP>=2.5<2.13
Remediation
Event History
Mar 30, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:07 AM
Description
Frequently Asked Questions
1
What is CVE-2022-24763?
CVE-2022-24763 is a denial-of-service vulnerability in the PJSIP library.
2
Which versions of PJSIP are affected by CVE-2022-24763?
Versions 2.12 and prior of PJSIP are affected by CVE-2022-24763.
3
How can I fix CVE-2022-24763?
To fix CVE-2022-24763, users are advised to update to a version of PJSIP that is not affected by the vulnerability.
4
Are there any known workarounds for CVE-2022-24763?
There are no known workarounds for CVE-2022-24763.
5
What is the severity of CVE-2022-24763?
CVE-2022-24763 has a severity rating of high.