PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known workarounds.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-835"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24763.json"
}[
{
"digest": {
"function_hash": "23112874292123438721122673683301241166",
"length": 2419.0
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2022-24763-010f5c90",
"target": {
"file": "pjlib-util/src/pjlib-util/xml.c",
"function": "xml_parse_node"
},
"source": "https://github.com/pjsip/pjproject/commit/856f87c2e97a27b256482dbe0d748b1194355a21"
},
{
"digest": {
"line_hashes": [
"298137472848914754553705263002548042059",
"256854082399797273380735969700505730638",
"151671903702646675619882133541944850855",
"166700460298304986497664136193760399315"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2022-24763-1d35935b",
"target": {
"file": "pjlib-util/src/pjlib-util/xml.c"
},
"source": "https://github.com/pjsip/pjproject/commit/856f87c2e97a27b256482dbe0d748b1194355a21"
}
]