PJSIP
cpe:2.3:a:pjsip:pjsip:*:*:*:*:*:*:*
- <= 2.16
An integer overflow vulnerability has been identified in PJSIP versions through 2.16, specifically in the media stream component. The issue arises when processing Session Description Protocol (SDP) with asymmetric 'ptime' configurations, leading to an incorrect buffer size allocation. This miscalculation can cause memory corruption or unexpected application crashes.
Exploitation of this vulnerability can result in memory corruption or unintended application termination.
Users can upgrade to PJSIP version 2.17, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.