PJSIP 是一个用 C 语言编写的免费开源多媒体通信库。在提交 c4a151a 之前,GnuTLS TLS 后端在解析对端证书的“主题备用名称”(Subject Alternative Name)扩展时存在栈缓冲区溢出漏洞(位于 中的 函数)。仅 GnuTLS 构建版本受影响(使用 参数编译的版本);OpenSSL 以及 Apple SecureTransport/Network.framework 构建版本不受影响。 在 TLS 握手后提取证书信息时,错误的缓冲区大小值可能导致过长的 SubjectAltNam
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57162 | 8.8 HIGH | PJSIP: Stack overflow parsing SDP a=crypto attributes |
| CVE-2026-57161 | 8.8 HIGH | PJSIP: Stack overflow handling Service-Route headers in a registration response |
| CVE-2026-57159 | 8.4 HIGH | PJSIP: SDP parser out-of-bounds write in remote payload-type map maintenance |
| CVE-2026-57164 | 8.3 HIGH | PJSIP: Heap overflow in the HTTP client |
| CVE-2026-57160 | 6.9 MEDIUM | PJSIP: SIP message header buffer overflow |
| CVE-2026-57165 | 6.3 MEDIUM | PJSIP: Pre-authentication overflow in the telnet CLI history |
| CVE-2026-57166 | 6.3 MEDIUM | PJSIP: Pre-authentication overflow in the telnet CLI error |
No comments yet