VDB

CVE-2022-24792

CVE-2022-24792 PUBLISHED CVSS 7.5 HIGH

PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV files. The vulnerability occurs when reading WAV file data chunks with length greater than 31-bit integers. The vulnerability does not affect 64-bit apps and should not affect apps that only plays trusted WAV files. A patch is available on the `master` branch of the `pjsip/project` GitHub repository. As a workaround, apps can reject a WAV file received from an unknown source or validate the file first.

EPSS 1.61% · 82.1th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
1.61%
82.1th percentile

Affected Products

VendorProductVersions
debiandebian_linux9.0, 10.0, 11.0
pjsippjproject<= 2.12
teluupjsip0

Timeline

  • Apr 25, 2022 CVE Published
  • Apr 26, 2022 EPSS Score
  • Jun 15, 2022 EPSS Score
  • Aug 4, 2022 EPSS Score
  • Nov 12, 2022 EPSS Score
  • Jan 1, 2023 EPSS Score
  • Feb 19, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 10, 2023 EPSS Score
  • May 30, 2023 EPSS Score
  • Sep 6, 2023 EPSS Score
  • Oct 26, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›