CVE-2022-24763

high
Published 2022-03-30 ยท Modified 2026-05-06
CVSS v3
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.5

Description

PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known workarounds.

Predictions

Exploit likelihood
83%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: GitHub Security Advisory ยท View original โ†— ยท CC-BY-4.0

OS impact

OSVersionStatusFixed in
debian debianbullseyefixed1:16.28.0~dfsg-0+deb11u1
debian debiansidfixed1:18.14.0~~rc1~dfsg+~cs6.12.40431414-1
debian debian9.0affected
debian debian10.0affected
debian debian11.0affected
debian debianbookwormfixed20230206.0~ds1-1

Application impact

VendorProductVersionsFixed
teluupjsip{"startIncluding":"2.5","endExcluding":"2.13"}2.13

References

CWEs

CWE-835

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.