From c0d221f307147d6e10c6f7292b4607f41d713ba4 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 22 Sep 2024 06:00:29 +0000 Subject: [ GLSA 202409-05 ] PJSIP: Heap Buffer Overflow Bug: https://bugs.gentoo.org/917463 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202409-05.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 glsa-202409-05.xml diff --git a/glsa-202409-05.xml b/glsa-202409-05.xml new file mode 100644 index 00000000..866c0e21 --- /dev/null +++ b/glsa-202409-05.xml @@ -0,0 +1,42 @@ + + + + PJSIP: Heap Buffer Overflow + A vulnerability has been discovered in PJSIP, which could lead to arbitrary code execution. + pjproject + 2024-09-22 + 2024-09-22 + 917463 + local and remote + + + 2.13.1 + 2.13.1 + + + +

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE.

+
+ +

Please review the CVE identifier referenced below for details.

+
+ +

Please review the CVE identifier referenced below for details.

+
+ +

There is no known workaround at this time.

+
+ +

All PJSIP users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-libs/pjproject-2.13.1" + +
+ + CVE-2023-27585 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad