Teluu PJSIP version 2.7.1 and earlier contains a Access of Null/Uninitialized Pointer vulnerability in pjmedia SDP parsing that can result in Crash. This attack appear to be exploitable via Sending a specially crafted message. This vulnerability appears to have been fixed in 2.7.2.
The product accesses or uses a pointer that has not been initialized.
Link | Tags |
---|---|
https://trac.pjsip.org/repos/ticket/2094 | patch vendor advisory |
https://trac.pjsip.org/repos/milestone/release-2.7.2 | vendor advisory |
https://www.debian.org/security/2018/dsa-4170 | third party advisory vendor advisory |
https://trac.pjsip.org/repos/ticket/2092 | vendor advisory |