PT-2026-23652 · Pjsip · Pjsip
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PJSIP versions prior to 2.17
Description
PJSIP, a multimedia communication library written in C, contains a heap use-after-free issue within its event subscription framework, specifically in the
evsub.c file. This issue is triggered by a presence unsubscription request—a SUBSCRIBE request with an Expires value of 0. Successful exploitation could lead to a crash or potentially code execution.Recommendations
Update to version 2.17 or later.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pjsip