Buffer Overflow Vulnerability in PJSIP DNS Resolver by PJSIP
CVE-2023-27585
What is CVE-2023-27585?
A buffer overflow vulnerability exists in the DNS resolver of PJSIP, an open-source multimedia communication library, impacting versions 2.13 and earlier. This issue, categorized under parsing the query record in the parse_query() function, does not affect users who do not utilize the PJSIP DNS resolver. A fix is provided in the master branch with commit d1c5e4d. Users are advised to mitigate potential risks by either patching the software or disabling DNS resolution by setting nameserver_count to zero in the PJSIP configuration, or opting for an external DNS resolver.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
pjproject <= 2.13
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
