Impact
An out‑of‑bounds read and write in the SDP negotiator can corrupt memory when a remote SIP offer or answer supplies an unexpected payload type number. The issue is limited to the remote payload‑type map maintenance feature and has not been shown to lead to code execution. The consequence is clear memory corruption and a resulting denial of service for the affected process.
Affected Systems
The vulnerability affects all builds of the PJSIP pjproject library that use the remote payload‑type map maintenance feature. It is present in all versions prior to Git commit 673b978, which introduced a bounds check. Products that enable the PJMEDIA_SDP_NEG_MAINTAIN_REMOTE_PT_MAP option are at risk while default builds remain unaffected.
Risk and Exploitability
The CVSS score of 8.4 highlights a serious impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploits yet. Nonetheless, the attack vector is remote: a crafted SDP message from an external party can trigger the flaw. An attacker would need to transmit a specifically constructed SDP offer or answer to an endpoint that has the feature enabled. Exacerbation occurs only when the feature is active, so risk is reduced in default configurations.
OpenCVE Enrichment