Cleartext transmission of sensitive information in pjsip - CVE-2022-39269

 

Cleartext transmission of sensitive information in pjsip - CVE-2022-39269

Published: November 14, 2022 / Updated: November 24, 2022


Vulnerability identifier: #VU69269
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-39269
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media to be sent insecurely. A remote attacker with ability to intercept network traffic can gain access to sensitive data.


Affected software

pjsip
Gentoo Linux
Debian Linux
net-libs/pjproject
asterisk (Debian package)

How to mitigate CVE-2022-39269

Install update from vendor's website.

pjsip - update to 2.13
net-libs/pjproject - update to 2.12.1
asterisk (Debian package) - update to 1:16.28.0~dfsg-0+deb11u2

External References

Related Security Bulletins