PT-2023-26568 · Pjsip+2 · Pjsip+2

Sauwming

·

Published

2023-10-06

·

Updated

2024-11-25

·

CVE-2023-38703

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PJSIP (affected versions not specified)
Description The issue affects applications that have SRTP capability (PJMEDIA HAS SRTP is set) and use underlying media transport other than UDP. A higher level transport is not synchronized with its lower level transport, which may introduce a use-after-free issue. The impact of this issue may range from unexpected application termination to control flow hijack/memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15954
ALT-PU-2024-16030
CVE-2023-38703
DLA-3696-1
DSA-5596-1
GHSA-F76W-FH7C-PC66

Affected Products

Alt Linux
Debian
Pjsip