PT-2026-26552 · Pjsip · Pjsip

Sauwming

·

Publicado

2026-03-20

·

Atualizado

2026-03-24

·

CVE-2026-32945

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PJSIP versions 2.16 and below
Description PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a Heap-based Buffer Overflow in the DNS parser's name length handler. This impacts applications using PJSIP’s built-in DNS resolver, such as those configured with pjsua config.nameserver or UaConfig.nameserver in PJSUA/PJSUA2. Users who rely on the operating system resolver (e.g., getaddrinfo()) by not configuring a nameserver, or those using an external resolver via pjsip resolver set ext resolver(), are not affected.
Recommendations Versions 2.16 and below: Upgrade to version 2.17 or disable DNS resolution in the PJSIP configuration by setting nameserver count to zero, or use an external resolver implementation.

Exploit

Correção

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32945
GHSA-JR2P-P2W4-RR9Q

Produtos afetados

Pjsip