CVE-2018-1000098

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
13/03/2018
Last modified:
20/03/2019

Description

Teluu PJSIP version 2.7.1 and earlier contains a Integer Overflow vulnerability in pjmedia SDP parsing that can result in Crash. This attack appear to be exploitable via Sending a specially crafted message. This vulnerability appears to have been fixed in 2.7.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:* 2.7.1 (including)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*