VDB

CVE-2021-41141

CVE-2021-41141 PUBLISHED CVSS 5.900000095367432 MEDIUM

PJSIP is a free and open source multimedia communication library written in the C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In various parts of PJSIP, when error/failure occurs, it is found that the function returns without releasing the currently held locks. This could result in a system deadlock, which cause a denial of service for the users. No release has yet been made which contains the linked fix commit. All versions up to an including 2.11.1 are affected. Users may need to manually apply the patch.

EPSS 1.37% · 69.9th percentile

Risk Scores

CVSS 3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
1.37%
69.9th percentile

Affected Products

VendorProductVersions
debiandebian_linux9.0
pjsippjproject<= 2.11.1
teluupjsip0

Timeline

  • Jan 4, 2022 CVE Published
  • Jan 5, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 23, 2022 EPSS Score
  • Jun 15, 2022 EPSS Score
  • Aug 9, 2022 EPSS Score
  • Oct 2, 2022 EPSS Score
  • Nov 25, 2022 EPSS Score
  • Jan 18, 2023 EPSS Score
  • Mar 12, 2023 EPSS Score
  • May 5, 2023 EPSS Score
  • Jun 28, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›