VDB

CVE-2022-24754

CVE-2022-24754 PUBLISHED CVSS 8.5 HIGH

PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and including 2.12 PJSIP there is a stack-buffer overflow vulnerability which only impacts PJSIP users who accept hashed digest credentials (credentials with data_type `PJSIP_CRED_DATA_DIGEST`). This issue has been patched in the master branch of the PJSIP repository and will be included with the next release. Users unable to upgrade need to check that the hashed digest data length must be equal to `PJSIP_MD5STRLEN` before passing to PJSIP.

EPSS 2.10% · 80.5th percentile

Risk Scores

CVSS 3.1
8.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
2.10%
80.5th percentile

Affected Products

VendorProductVersions
debiandebian_linux9.0
teluupjsip0
pjsippjproject<= 2.12

Timeline

  • Mar 11, 2022 CVE Published
  • Mar 12, 2022 EPSS Score
  • May 3, 2022 EPSS Score
  • Jun 23, 2022 EPSS Score
  • Oct 5, 2022 EPSS Score
  • Nov 26, 2022 EPSS Score
  • Jan 16, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 29, 2023 EPSS Score
  • Jun 20, 2023 EPSS Score
  • Aug 11, 2023 EPSS Score
  • Oct 1, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›