Mar 03 2022

Popular open-source PJSIP library is affected by critical flaws

Category: Security vulnerabilitiesDISC @ 10:46 am

Researchers from JFrog’s Security Research team discovered five vulnerabilities in the popular PJSIP open-source multimedia communication library.

PJSIP is a communication library written in C language implementing standard-based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. It combines signaling protocol (SIP) with rich multimedia framework and NAT traversal functionality into high level API that is portable and suitable for almost any type of systems ranging from desktops, embedded systems, to mobile handsets.

PJSIP supports audio, video, presence, and instant messaging, the APT supplied by the library can be used by IP telephony applications, including VoIP devices.

Many popular communication applications use the library, including WhatsApp, BlueJeans and Asterisk.

An attacker can exploit the flaws to gain arbitrary code execution on devices running applications using the vulnerable library or to trigger a denial-of-service (DoS) condition.

The list of the flaws discovered in the PJSIP library:

Open Source Security: Your Network More Secure With Open Source Tools 

Tags: critical flaws, open-source PJSIP

Leave a Reply

You must be logged in to post a comment. Login now.