PJSIP 是一个用 C 语言编写的免费开源多媒体通信库。在提交 acc03b5 之前,PJSUA 在处理注册响应中的 Service-Route 头部时存在栈缓冲区溢出漏洞(位于 pjsua_acc.c 中的 函数)。该漏洞影响使用 PJSUA/PJSUA2 账户 API 进行注册的应用程序(默认注册路径)。 来自针对 REGISTER 请求的 2xx 响应中的 Service-Route URI 被存储到一个固定大小的数组中,且未对头部数量进行限制;如果注册服务器返回过量的 Service-Route 头部,就
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57163 | 8.8 HIGH | PJSIP: Stack overflow parsing a TLS peer certificate's SubjectAltName in GnuTLS backend |
| CVE-2026-57162 | 8.8 HIGH | PJSIP: Stack overflow parsing SDP a=crypto attributes |
| CVE-2026-57159 | 8.4 HIGH | PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance |
| CVE-2026-57164 | 8.3 HIGH | PJSIP: Heap overflow in the HTTP client |
| CVE-2026-57160 | 6.9 MEDIUM | PJSIP: SIP message header buffer overflow |
| CVE-2026-57165 | 6.3 MEDIUM | PJSIP: Pre-authentication overflow in the telnet CLI history |
| CVE-2026-57166 | 6.3 MEDIUM | PJSIP: Pre-authentication overflow in the telnet CLI error |
No comments yet