cve/2021/CVE-2021-43300.md

18 lines
679 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2021-43300](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43300)
![](https://img.shields.io/static/v1?label=Product&message=pjsip&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%3D%202.11.1%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-121&color=brighgreen)
### Description
Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/nscuro/gotalias