Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-27585


PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not utilise PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue in CVE-2022-24793 is in `parse_rr()`. A patch is available as commit `d1c5e4d` in the `master` branch. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver implementation instead.


Published

2023-03-14T17:15:19.587

Last Modified

2024-11-21T07:53:12.153

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-120
    CWE-122

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application teluu pjsip < 2.13 Yes

References