PT-2020-13765 · Meetecho+1 · Janus-Gateway+1

Mikhail Evdokimov

·

Published

2020-06-10

·

Updated

2021-03-04

·

CVE-2020-13901

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions janus-gateway versions through 0.10.0
Description A stack-based buffer overflow issue was discovered in the janus sdp merge function in sdp.c. This issue can be exploited due to the lack of proper validation of input data.
Recommendations For versions through 0.10.0, consider disabling the janus sdp merge function as a temporary workaround until a patch is available. Restrict access to the sdp.c module to minimize the risk of exploitation. Avoid using the janus-gateway until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2180
CVE-2020-13901

Affected Products

Alt Linux
Janus-Gateway