PJSIP 是一个免费的开源多媒体通信库,使用 C 语言编写。在提交 d6a0e7f 之前, 函数(位于 )中可能存在缓冲区溢出漏洞。该函数负责序列化通用数组头字段(如 Allow、Require、Supported 和 Unsupported)。在某些输出缓冲区的边界条件下,该函数可能会在缓冲区末尾之外多写一个字节。该漏洞主要影响需要解析并重新序列化传入 SIP 请求的应用程序(例如代理服务器、SBC 或 B2BUA),其中远程对等方可以影响序列化后的消息内容。该越界写入仅涉及一个固定的字节;尚未证明可由此实现代
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57163 | 8.8 HIGH | PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend |
| CVE-2026-57162 | 8.8 HIGH | PJSIP: Stack overflow parsing SDP a=crypto attributes |
| CVE-2026-57161 | 8.8 HIGH | PJSIP: Stack overflow handling Service-Route headers in a registration response |
| CVE-2026-57159 | 8.4 HIGH | PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance |
| CVE-2026-57164 | 8.3 HIGH | PJSIP: Heap overflow in the HTTP client |
| CVE-2026-57165 | 6.3 MEDIUM | PJSIP: Pre-authentication overflow in the telnet CLI history |
| CVE-2026-57166 | 6.3 MEDIUM | PJSIP: Pre-authentication overflow in the telnet CLI error |
No comments yet