UBUNTU-CVE-2022-24764
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-24764
UBUNTU-CVE-2022-24764
Summary:
Details: PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability that affects PJSUA2 users or users that call the API `pjmedia_sdp_print(), pjmedia_sdp_media_print()`. Applications that do not use PJSUA2 and do not directly call `pjmedia_sdp_print()` or `pjmedia_sdp_media_print()` should not be affected. A patch is available on the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.
References: https://ubuntu.com/security/CVE-2022-24764, https://github.com/pjsip/pjproject/commit/560a1346f87aabe126509bb24930106dea292b00, https://github.com/pjsip/pjproject/security/advisories/GHSA-f5qg-pqcg-765m, https://ubuntu.com/security/notices/USN-6422-1, https://www.cve.org/CVERecord?id=CVE-2022-24764
Affected packages
Package
Name: pjproject
Purl: pkg:deb/ubuntu/[email protected]+deb8u1ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial
Affected ranges
Type: ECOSYSTEM
Events:
