CVE-2022-24792
PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV files. The vulnerability occurs when reading WAV file data chunks with length greater than 31-bit integers. The vulnerability does not affect 64-bit apps and should not affect apps that only plays trusted WAV files. A patch is available on the `master` branch of the `pjsip/project` GitHub repository. As a workaround, apps can reject a WAV file received from an unknown source or validate the file first.
EPSS 1.61% · 82.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| debian | debian_linux | 9.0, 10.0, 11.0 |
| pjsip | pjproject | <= 2.12 |
| teluu | pjsip | 0 |
Timeline
- Apr 25, 2022 CVE Published
- Apr 26, 2022 EPSS Score
- Jun 15, 2022 EPSS Score
- Aug 4, 2022 EPSS Score
- Nov 12, 2022 EPSS Score
- Jan 1, 2023 EPSS Score
- Feb 19, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 10, 2023 EPSS Score
- May 30, 2023 EPSS Score
- Sep 6, 2023 EPSS Score
- Oct 26, 2023 EPSS Score
References
- https://github.com/pjsip/pjproject/security/advisories/GHSA-rwgw-vwxg-q799 url
- https://github.com/pjsip/pjproject/commit/947bc1ee6d05be10204b918df75a503415fd3213 url
- [debian-lts-announce] 20220531 [SECURITY] [DLA 3036-1] pjproject security update mailing-list
- GLSA-202210-37 vendor-advisory
- [debian-lts-announce] 20221117 [SECURITY] [DLA 3194-1] asterisk security update mailing-list
- DSA-5285 vendor-advisory