Uncaught Exception in pjsip - CVE-2021-32686
Published: July 26, 2021
Vulnerability identifier: #VU55295
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32686
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The
vulnerability exists due to uncaught exception in pjsip when processing TLS handshake. A remote
attacker can initiate TLS connection with the software and then destroy
the socket during handshake, causing the application to crash.
Affected software
pjsip
Gentoo Linux
Ubuntu
Asterisk Open Source
Certified Asterisk
pjproject (Ubuntu package)
net-libs/pjproject
asterisk (Debian package)
Gentoo Linux
Ubuntu
Asterisk Open Source
Certified Asterisk
pjproject (Ubuntu package)
net-libs/pjproject
asterisk (Debian package)
How to mitigate CVE-2021-32686
Install updates from vendor's website.
pjsip - update to 2.11.1
Asterisk Open Source - addressed in versions 13.38.3, 16.19.1, 17.9.4, 18.5.1
Certified Asterisk - update to 16.8-cert10
pjproject (Ubuntu package) - addressed in versions 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1, 2.7.2~dfsg-1ubuntu0.1~esm1
net-libs/pjproject - update to 2.12.1
asterisk (Debian package) - update to 1:16.16.1~dfsg-1+deb11u1
Asterisk Open Source - addressed in versions 13.38.3, 16.19.1, 17.9.4, 18.5.1
Certified Asterisk - update to 16.8-cert10
pjproject (Ubuntu package) - addressed in versions 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1, 2.7.2~dfsg-1ubuntu0.1~esm1
net-libs/pjproject - update to 2.12.1
asterisk (Debian package) - update to 1:16.16.1~dfsg-1+deb11u1