Integer overflow in pjproject (Debian package) - CVE-2018-1000098
Published: April 12, 2018
Vulnerability identifier: #VU11775
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000098
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in pjmedia SDP parsing due to integer overflow. A remote attacker can submit a specially crafted message, trigger memory corruption and cause the service to crash.
The weakness exists in pjmedia SDP parsing due to integer overflow. A remote attacker can submit a specially crafted message, trigger memory corruption and cause the service to crash.
Affected software
pjproject (Debian package)
pjproject (Ubuntu package)
asterisk
Debian Linux
Ubuntu
Fedora
pjproject (Ubuntu package)
asterisk
Debian Linux
Ubuntu
Fedora
How to mitigate CVE-2018-1000098
Update to versions 2.7.2~dfsg-1 or 2.5.5~dfsg-6+deb9u1.
pjproject (Ubuntu package) - addressed in versions 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1, 2.7.2~dfsg-1ubuntu0.1~esm1
asterisk - update to 14.7.6-2.fc27
asterisk - update to 14.7.6-2.fc27