VDB

CVE-2022-21722

CVE-2022-21722 PUBLISHED CVSS 9.100000381469727 CRITICAL

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In version 2.11.1 and prior, there are various cases where it is possible that certain incoming RTP/RTCP packets can potentially cause out-of-bound read access. This issue affects all users that use PJMEDIA and accept incoming RTP/RTCP. A patch is available as a commit in the `master` branch. There are no known workarounds.

EPSS 2.40% · 82.9th percentile

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS Score
2.40%
82.9th percentile

Affected Products

VendorProductVersions
pjsippjproject*
teluupjsip0
debiandebian_linux10.0, 9.0

Timeline

  • Jan 27, 2022 CVE Published
  • Feb 8, 2022 EPSS Score
  • Apr 2, 2022 EPSS Score
  • May 24, 2022 EPSS Score
  • Sep 7, 2022 EPSS Score
  • Oct 30, 2022 EPSS Score
  • Dec 21, 2022 EPSS Score
  • Feb 12, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 28, 2023 EPSS Score
  • Jul 20, 2023 EPSS Score
  • Sep 10, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›