Integer overflow in pjproject (Debian package) - CVE-2017-16875

 

Integer overflow in pjproject (Debian package) - CVE-2017-16875

Published: April 12, 2018


Vulnerability identifier: #VU11774
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16875
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the ioqueue component due to issuing a double key unregistration after a remote attacker initiates a socket connection with specific settings and sequences. A remote attacker can trigger integer overflow, ioqueue backends to reject future key registrations and cause the service to crash.

Affected software

pjproject (Debian package)
pjproject (Ubuntu package)
Debian Linux
Ubuntu

How to mitigate CVE-2017-16875

Update to versions 2.7.2~dfsg-1 or 2.5.5~dfsg-6+deb9u1.

pjproject (Ubuntu package) - addressed in versions 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1, 2.7.2~dfsg-1ubuntu0.1~esm1

External References

Related Security Bulletins