Skip to content

Potential out-of-bounds read when parsing RTCP BYE message

High
sauwming published GHSA-3qx3-cg72-wrh9 Dec 22, 2021

Package

No package listed

Affected versions

2.11.1 or lower

Patched versions

2.12 or later

Description

If the incoming RTCP BYE message contains a reason's length, this declared length is not checked against the actual received packet size, potentially resulting in an out-of-bound read access.

Impact

It affects all users that use PJMEDIA and RTCP. A malicious actor can send a RTCP BYE message with an invalid reason length.

Patches

The patch is available as commit 8b621f1 in the master branch.

For more information

If you have any questions or comments about this advisory:
Email us at [email protected]

Severity

High

CVE ID

CVE-2021-43804

Weaknesses

No CWEs

Credits