Arbitrary Code Execution Vulnerability in PJSIP PJSUA2 SDK for Android
CVE-2015-2003
9.8CRITICAL
What is CVE-2015-2003?
The PJSIP PJSUA2 SDK for Android contains a security flaw that may allow attackers to execute arbitrary code. This issue arises from the improper handling of a finalize method within a Serializable class, which can mistakenly pass an attacker-controlled pointer to a native function. Exploiting this vulnerability could enable unauthorized access and manipulation of device functionality, posing serious risks to application security and user data.
