CVE-2022-24786

critical

Description

PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not parse incoming RTCP feedback RPSI (Reference Picture Selection Indication) packet, but any app that directly uses pjmedia_rtcp_fb_parse_rpsi() will be affected. A patch is available in the `master` branch of the `pjsip/pjproject` GitHub repository. There are currently no known workarounds.

References

https://www.debian.org/security/2022/dsa-5285

https://security.gentoo.org/glsa/202210-37

https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html

https://github.com/pjsip/pjproject/security/advisories/GHSA-vhxv-phmx-g52q

https://github.com/pjsip/pjproject/commit/11559e49e65bdf00922ad5ae28913ec6a198d508

Details

Source: Mitre, NVD

Published: 2022-04-06

Updated: 2023-02-02

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical