Integer overflow in pjproject (Debian package) - CVE-2017-16875
Published: April 12, 2018
Vulnerability identifier: #VU11774
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16875
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the ioqueue component due to issuing a double key unregistration after a remote attacker initiates a socket connection with specific settings and sequences. A remote attacker can trigger integer overflow, ioqueue backends to reject future key registrations and cause the service to crash.
The weakness exists in the ioqueue component due to issuing a double key unregistration after a remote attacker initiates a socket connection with specific settings and sequences. A remote attacker can trigger integer overflow, ioqueue backends to reject future key registrations and cause the service to crash.
Affected software
pjproject (Debian package)
pjproject (Ubuntu package)
Debian Linux
Ubuntu
pjproject (Ubuntu package)
Debian Linux
Ubuntu
How to mitigate CVE-2017-16875
Update to versions 2.7.2~dfsg-1 or 2.5.5~dfsg-6+deb9u1.
pjproject (Ubuntu package) - addressed in versions 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1, 2.7.2~dfsg-1ubuntu0.1~esm1