CVE-2022-24754
9.8
CRITICAL
CVSS 3.1
EPSS 2.0%
描述
PJSIP is a free and open source multimedia communication library written in C language. In versions prior to and including 2.12 PJSIP there is a stack-buffer overflow vulnerability which only impacts PJSIP users who accept hashed digest credentials (credentials with data_type `PJSIP_CRED_DATA_DIGEST`). This issue has been patched in the master branch of the PJSIP repository and will be included with the next release. Users unable to upgrade need to check that the hashed digest data length must be equal to `PJSIP_MD5STRLEN` before passing to PJSIP.
如何修補 CVE-2022-24754
要修補 CVE-2022-24754,請將受影響套件升級到下列已修補版本。
- —升級至 2.12.1-r0 或更新版本
- —升級至 20210112.2.b757bac~ds1-1+deb11u1 或更新版本
CVE-2022-24754 正在被利用嗎?
低 — EPSS 為 2.0%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.12.1-r0
- from 0, < 20210112.2.b757bac~ds1-1+deb11u1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |