CVE-2022-39244

7.5 HIGH
Published: October 06, 2022 Modified: November 04, 2025

Description

PJSIP is a free and open source multimedia communication library written in C. In versions of PJSIP prior to 2.13 the PJSIP parser, PJMEDIA RTP decoder, and PJMEDIA SDP parser are affeced by a buffer overflow vulnerability. Users connecting to untrusted clients are at risk. This issue has been patched and is available as commit c4d3498 in the master branch and will be included in releases 2.13 and later. Users are advised to upgrade. There are no known workarounds for this issue.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae
Source: security-advisories@github.com
Patch Third Party Advisory
https://github.com/pjsip/pjproject/security/advisories/GHSA-fq45-m3f7-3mhj
Source: security-advisories@github.com
Third Party Advisory
https://security.gentoo.org/glsa/202210-37
Source: security-advisories@github.com
Third Party Advisory
https://www.debian.org/security/2023/dsa-5358
Source: security-advisories@github.com
https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Third Party Advisory
https://github.com/pjsip/pjproject/security/advisories/GHSA-fq45-m3f7-3mhj
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://security.gentoo.org/glsa/202210-37
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.debian.org/security/2023/dsa-5358
Source: af854a3a-2127-422b-91ae-364da2661108

13 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.5 / 10.0
EPSS (Exploit Probability)
0.2%
45th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

pjsip