CVE-2017-16875

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/11/2017
Last modified:
20/04/2025

Description

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. The ioqueue component may issue a double key unregistration after an attacker initiates a socket connection with specific settings and sequences. Such double key unregistration will trigger an integer overflow, which may cause ioqueue backends to reject future key registrations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:* 2.7.1 (excluding)