PT-2026-26586 · Pjsip · Pjsip
Sauwming
·
Published
2026-03-20
·
Updated
2026-03-22
·
CVE-2026-33069
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PJSIP versions 2.16 and below
Description
PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a cascading out-of-bounds heap read in the
pjsip multipart parse() function. After boundary string matching, the curptr variable is advanced past the delimiter without verifying it has not reached the buffer end, allowing 1-2 bytes of adjacent heap memory to be read. All applications that process incoming SIP messages with multipart bodies or SDP content are potentially affected.Recommendations
Upgrade to version 2.17.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pjsip