PT-2018-9278 · Teluu+1 · Pjsip+1

Published

2018-03-13

·

Updated

2026-03-24

·

CVE-2018-1000099

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Teluu PJSIP versions 2.7.1 and earlier
Description: The issue is related to a null or uninitialized pointer access in the pjmedia SDP parsing component, which can cause a crash. This can be exploited by sending a specially crafted message.
Recommendations: For versions 2.7.1 and earlier, update to version 2.7.2 or later to resolve the issue.

Fix

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

ALT-PU-2018-3676
CVE-2018-1000099
DSA-4170-1
USN-8122-1

Affected Products

Alt Linux
Pjsip