PT-2021-14457 · Pjsip+2 · Pjsip+2
Sauwming
·
Published
2021-03-10
·
Updated
2026-03-24
·
CVE-2021-21375
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PJSIP versions 2.10 and earlier
Description
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP, after an initial INVITE has been sent, when two 183 responses are received, with the first one causing negotiation failure, a crash will occur. This results in a denial of service.
Recommendations
For PJSIP versions 2.10 and earlier, update to a version later than 2.10 to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Improper Check for Exceptional Conditions
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Pjsip
Ubuntu