Out-of-bounds read in multipart parsing in PJSIP
CVE-2022-21723
9.1CRITICAL
What is CVE-2022-21723?
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the master branch. There are no known workarounds.
Affected Version(s)
pjproject <= 2.11.1
