CVE-2021-37706

NameCVE-2021-37706
DescriptionPJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not checked before performing a subtraction operation, potentially resulting in an integer underflow scenario. This issue affects all users that use STUN. A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s machine. Users are advised to upgrade as soon as possible. There are no known workarounds.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-2962-1, DLA-3194-1, DLA-3549-1, DLA-3887-1, DSA-5285-1
Debian Bugs1014998, 1057379

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
asterisk (PTS)jessie, jessie (lts)1:11.13.1~dfsg-2+deb8u8vulnerable
stretch (security)1:13.14.1~dfsg-2+deb9u6fixed
stretch (lts), stretch1:13.14.1~dfsg-2+deb9u10fixed
buster, buster (lts)1:16.28.0~dfsg-0+deb10u5fixed
buster (security)1:16.28.0~dfsg-0+deb10u4fixed
bullseye1:16.28.0~dfsg-0+deb11u4fixed
bullseye (security)1:16.28.0~dfsg-0+deb11u5fixed
sid1:22.0.0~dfsg+~cs6.14.60671435-1fixed
pjproject (PTS)jessie, jessie (lts)2.1.0.0.ast20130823-1+deb8u1vulnerable
stretch (security)2.5.5~dfsg-6+deb9u5fixed
stretch (lts), stretch2.5.5~dfsg-6+deb9u9fixed
ring (PTS)stretch (security), stretch (lts), stretch20161221.2.7bd7d91~dfsg1-1+deb9u1vulnerable
buster (security), buster, buster (lts)20190215.1.f152c98~ds1-1+deb10u2fixed
bullseye20210112.2.b757bac~ds1-1vulnerable
bullseye (security)20210112.2.b757bac~ds1-1+deb11u1fixed
bookworm20230206.0~ds2-1.1fixed
sid20231201.0~ds1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
asterisksourcejessie(unfixed)end-of-life
asterisksourcestretch(not affected)
asterisksourcebuster1:16.28.0~dfsg-0+deb10u1DLA-3194-1
asterisksourcebullseye1:16.28.0~dfsg-0+deb11u1DSA-5285-1
asterisksource(unstable)1:18.10.1~dfsg+~cs6.10.40431411-1
pjprojectsourcejessie(unfixed)end-of-life
pjprojectsourcestretch2.5.5~dfsg-6+deb9u3DLA-2962-1
pjprojectsource(unstable)(unfixed)
ringsourcestretch(unfixed)end-of-life
ringsourcebuster20190215.1.f152c98~ds1-1+deb10u2DLA-3549-1
ringsourcebullseye20210112.2.b757bac~ds1-1+deb11u1DLA-3887-1
ringsource(unstable)20230206.0~ds1-11014998, 1057379

Notes

[stretch] - asterisk <not-affected> (Vulnerable code not present)
https://issues.asterisk.org/jira/browse/ASTERISK-29945
https://downloads.asterisk.org/pub/security/AST-2022-004.html
https://github.com/pjsip/pjproject/security/advisories/GHSA-2qpg-f6wf-w984
Fixed by: https://github.com/pjsip/pjproject/commit/15663e3f37091069b8c98a7fce680dc04bc8e865
Superseeded by: https://github.com/savoirfairelinux/pjproject/commit/4cea72a4db91c6f0a0984b82edf2f147eda289aa

Search for package or bug name: Reporting problems