PJSIP 是一个用 C 语言编写的免费开源多媒体通信库。在提交 673b978 之前,如果启用了“远程有效载荷类型(payload-type)映射维护”功能,SDP 协商器中可能会发生远程越界读取和写入。 中的 函数直接使用从远程 SDP 提供或应答中获取的有效载荷类型编号来索引固定大小的内部表格,且缺乏充分的边界检查,因此精心构造的远程 SDP 可能导致内存访问超出这些表格的范围。该漏洞的实际影响是内存损坏和服务拒绝(DoS);目前尚未证明会导致代码执行。该代码路径仅在启用 时才会被触发。默认情况下该功能处于禁
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57163 | 8.8 HIGH | PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend |
| CVE-2026-57162 | 8.8 HIGH | PJSIP: Stack overflow parsing SDP a=crypto attributes |
| CVE-2026-57161 | 8.8 HIGH | PJSIP: Stack overflow handling Service-Route headers in a registration response |
| CVE-2026-57164 | 8.3 HIGH | PJSIP: Heap overflow in the HTTP client |
| CVE-2026-57160 | 6.9 MEDIUM | PJSIP: SIP message header buffer overflow |
| CVE-2026-57165 | 6.3 MEDIUM | PJSIP: Pre-authentication overflow in the telnet CLI history |
| CVE-2026-57166 | 6.3 MEDIUM | PJSIP: Pre-authentication overflow in the telnet CLI error |
No comments yet