Skip to content

Use-after-free in SRTP media transport

High
sauwming published GHSA-f76w-fh7c-pc66 Oct 6, 2023

Package

No package listed

Affected versions

2.13.1 or lower

Patched versions

2.14

Description

SRTP is a higher level media transport which is stacked upon a lower level media transport such as UDP and ICE. Currently a higher level transport is not synchronized with its lower level transport that may introduce use-after-free issue.

Impact

This vulnerability affects applications that have SRTP capability (PJMEDIA_HAS_SRTP is set) and use underlying media transport other than UDP. This vulnerability’s impact may range from unexpected application termination to control flow hijack/memory corruption.

Patches

The patch is available as commit 6dc9b8c in the master branch.

For more information

If you have any questions or comments about this advisory:
Email us at security@pjsip.org

Severity

High

CVE ID

CVE-2023-38703

Weaknesses

No CWEs