VDB

CVE-2021-32686

CVE-2021-32686 PUBLISHED

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP before version 2.11.1, there are a couple of issues found in the SSL socket. First, a race condition between callback and destroy, due to the accepted socket having no group lock. Second, the SSL socket parent/listener may get destroyed during handshake. Both issues were reported to happen intermittently in heavy load TLS connections. They cause a crash, resulting in a denial of service. These are fixed in version 2.11.1.

EPSS 1.68% · 82.5th percentile

Risk Scores

EPSS Score
1.68%
82.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSpjproject0, 2.1.0.0.ast20130823-1, 2.1.0.0.ast20130823-1+deb8u1build0.16.04.1
Ubuntu:18.04:LTSpjproject2.7.2~dfsg-1, 0, *

Timeline

  • Jul 22, 2021 CVE Published
  • Jul 24, 2021 EPSS Score
  • Sep 21, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 18, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 16, 2022 EPSS Score
  • Sep 13, 2022 EPSS Score
  • Nov 11, 2022 EPSS Score
  • Jan 9, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›