CVE-2021-21375
In PJSIP version 2.10 and earlier, after an initial INVITE has been sent, when two 183 responses are received, with the first one causing negotiation failure, a crash will occur.
Does this matter?
Lower severity and a low EPSS score (2.08%). Track it; it rarely justifies an emergency change on its own.
Description
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP version 2.10 and earlier, after an initial INVITE has been sent, when two 183 responses are received, with the first one causing negotiation failure, a crash will occur. This results in a denial of service.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400, CWE-754
- Affected
- teluu/pjsip · debian/debian linux
- Source
- security-advisories@github.com
References
- https://github.com/pjsip/pjproject/commit/97b3d7addbaa720b7ddb0af9bf6f3e443e664365Patch, Third Party Advisory
- https://github.com/pjsip/pjproject/security/advisories/GHSA-hvq6-f89p-frvpExploit, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00023.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00020.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-42Third Party Advisory
- https://github.com/pjsip/pjproject/commit/97b3d7addbaa720b7ddb0af9bf6f3e443e664365Patch, Third Party Advisory
- https://github.com/pjsip/pjproject/security/advisories/GHSA-hvq6-f89p-frvpExploit, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/04/msg00023.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/05/msg00020.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-42Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.