USN-8122-1
Dashboard / Vulnerabilities / USN-8122-1
USN-8122-1
Summary: pjproject vulnerabilities
Details: Youngsung Kim discovered that PJSIP did not properly parse numeric header fields in SIP messages. A remote attacker could use this issue to cause PJSIP to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-16872) Peter Koletzki discovered that PJSIP did not properly handle certain connection requests. A remote attacker could possibly use this issue to cause PJSIP to enter an unrecoverable state and reject further connections, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-16875) Alfred Farrugia, Sandro Gauci, and Kevin Harwell discovered that PJSIP did not properly parse certain SDP messages. A remote attacker could possibly use this issue to cause PJSIP to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2018-1000098, CVE-2018-1000099) Lauri Vänskä discovered that PJSIP did not verify hostnames when reusing TLS connections. If a remote attacker were able to intercept communication, this flaw could possibly be exploited to view sensitive information. (CVE-2020-15260) It was discovered that PJSIP did not properly handle certain sequences of SDP messages. A remote attacker could possibly use this issue to cause PJSIP to crash, resulting in a denial of service. (CVE-2021-21375) It was discovered that the SSL socket implementation in PJSIP contained a race condition. A remote attacker could possibly use this issue to cause PJSIP to crash, resulting in a denial of service. This issue was only addressed in Ubuntu 18.04 LTS. (CVE-2021-32686) It was discovered that PJSIP did not properly parse certain STUN messages. A remote attacker could use this issue to cause PJSIP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-37706) Uriya Yavnieli discovered that PJSIP did not properly manage memory under certain conditions. A remote attacker could use this issue to cause PJSIP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-43299, CVE-2021-43300, CVE-2021-43301, CVE-2021-43302, CVE-2021-43303) It was discovered that PJSIP did not properly manage memory when processing ICE session credentials. A remote attacker could use this issue to cause PJSIP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-25994)
References: https://ubuntu.com/security/notices/USN-8122-1, https://ubuntu.com/security/CVE-2017-16872, https://ubuntu.com/security/CVE-2017-16875, https://ubuntu.com/security/CVE-2018-1000098, https://ubuntu.com/security/CVE-2018-1000099, https://ubuntu.com/security/CVE-2020-15260, https://ubuntu.com/security/CVE-2021-21375, https://ubuntu.com/security/CVE-2021-32686, https://ubuntu.com/security/CVE-2021-37706, https://ubuntu.com/security/CVE-2021-43299, https://ubuntu.com/security/CVE-2021-43300, https://ubuntu.com/security/CVE-2021-43301, https://ubuntu.com/security/CVE-2021-43302, https://ubuntu.com/security/CVE-2021-43303, https://ubuntu.com/security/CVE-2026-25994
Affected packages
Package
Name: pjproject
Purl: pkg:deb/ubuntu/pjproject?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
