PT-2026-26552 · Pjsip · Pjsip
Sauwming
·
Publicado
2026-03-20
·
Atualizado
2026-03-24
·
CVE-2026-32945
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PJSIP versions 2.16 and below
Description
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a Heap-based Buffer Overflow in the DNS parser's name length handler. This impacts applications using PJSIP’s built-in DNS resolver, such as those configured with
pjsua config.nameserver or UaConfig.nameserver in PJSUA/PJSUA2. Users who rely on the operating system resolver (e.g., getaddrinfo()) by not configuring a nameserver, or those using an external resolver via pjsip resolver set ext resolver(), are not affected.Recommendations
Versions 2.16 and below: Upgrade to version 2.17 or disable DNS resolution in the PJSIP configuration by setting
nameserver count to zero, or use an external resolver implementation.Exploit
Correção
Heap Based Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pjsip