UBUNTU-CVE-2022-21723

Source
https://ubuntu.com/security/CVE-2022-21723
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-21723.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2022-21723
Related
Published
2022-01-27T00:15:00Z
Modified
2024-10-15T14:09:45Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the master branch. There are no known workarounds.

References

Affected packages

Ubuntu:Pro:16.04:LTS / pjproject

Package

Name
pjproject
Purl
pkg:deb/ubuntu/pjproject?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.1.0.0.ast20130823-1
2.1.0.0.ast20130823-1+deb8u1build0.16.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / pjproject

Package

Name
pjproject
Purl
pkg:deb/ubuntu/pjproject?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.6~dfsg-2
2.7~dfsg-1
2.7.1~dfsg-1
2.7.1~dfsg-1build1
2.7.2~dfsg-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / ring

Package

Name
ring
Purl
pkg:deb/ubuntu/ring?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20180228.1.503da2b~ds1-1ubuntu0.1~esm1

Affected versions

20170803.*

20170803.2.5fcfe3f~dfsg1-1

20171024.*

20171024.1.eadbdeb~ds1-1

20171129.*

20171129.2.cf5bbff~ds1-1
20171129.2.cf5bbff~ds1-2

20180119.*

20180119.1.9e06f94~ds1-1
20180119.1.9e06f94~ds1-3

20180222.*

20180222.1.7bffde2~ds2-2

20180228.*

20180228.1.503da2b~ds1-1
20180228.1.503da2b~ds1-1build1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "20180228.1.503da2b~ds1-1ubuntu0.1~esm1",
            "binary_name": "ring"
        },
        {
            "binary_version": "20180228.1.503da2b~ds1-1ubuntu0.1~esm1",
            "binary_name": "ring-daemon"
        },
        {
            "binary_version": "20180228.1.503da2b~ds1-1ubuntu0.1~esm1",
            "binary_name": "ring-daemon-dbgsym"
        },
        {
            "binary_version": "20180228.1.503da2b~ds1-1ubuntu0.1~esm1",
            "binary_name": "ring-dbgsym"
        }
    ]
}

Ubuntu:20.04:LTS / ring

Package

Name
ring
Purl
pkg:deb/ubuntu/ring?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1

Affected versions

20190215.*

20190215.1.f152c98~ds1-1
20190215.1.f152c98~ds1-1build1
20190215.1.f152c98~ds1-1build2

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1",
            "binary_name": "jami"
        },
        {
            "binary_version": "20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1",
            "binary_name": "jami-daemon"
        },
        {
            "binary_version": "20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1",
            "binary_name": "jami-daemon-dbgsym"
        },
        {
            "binary_version": "20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1",
            "binary_name": "jami-dbgsym"
        },
        {
            "binary_version": "20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1",
            "binary_name": "ring"
        },
        {
            "binary_version": "20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1",
            "binary_name": "ring-daemon"
        }
    ]
}