Uncaught Exception in pjsip - CVE-2021-32686

 

Uncaught Exception in pjsip - CVE-2021-32686

Published: July 26, 2021


Vulnerability identifier: #VU55295
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32686
CWE-ID: CWE-248
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to uncaught exception in pjsip when processing TLS handshake. A remote attacker can initiate TLS connection with the software and then destroy the socket during handshake, causing the application to crash.


Affected software

pjsip
Gentoo Linux
Ubuntu
Asterisk Open Source
Certified Asterisk
pjproject (Ubuntu package)
net-libs/pjproject
asterisk (Debian package)

How to mitigate CVE-2021-32686

Install updates from vendor's website.

pjsip - update to 2.11.1
Asterisk Open Source - addressed in versions 13.38.3, 16.19.1, 17.9.4, 18.5.1
Certified Asterisk - update to 16.8-cert10
pjproject (Ubuntu package) - addressed in versions 2.1.0.0.ast20130823-1+deb8u1ubuntu0.1~esm1, 2.7.2~dfsg-1ubuntu0.1~esm1
net-libs/pjproject - update to 2.12.1
asterisk (Debian package) - update to 1:16.16.1~dfsg-1+deb11u1

External References

Related Security Bulletins