PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJSIP's XML parsing in their apps. Users are advised to update. There are no known workarounds.
{
"cwe_ids": [
"CWE-835"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24763.json"
}[
{
"target": {
"file": "pjlib-util/src/pjlib-util/xml.c",
"function": "xml_parse_node"
},
"digest": {
"length": 2419.0,
"function_hash": "23112874292123438721122673683301241166"
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/pjsip/pjproject/commit/856f87c2e97a27b256482dbe0d748b1194355a21",
"id": "CVE-2022-24763-010f5c90",
"signature_type": "Function"
},
{
"target": {
"file": "pjlib-util/src/pjlib-util/xml.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"298137472848914754553705263002548042059",
"256854082399797273380735969700505730638",
"151671903702646675619882133541944850855",
"166700460298304986497664136193760399315"
]
},
"signature_version": "v1",
"deprecated": false,
"source": "https://github.com/pjsip/pjproject/commit/856f87c2e97a27b256482dbe0d748b1194355a21",
"id": "CVE-2022-24763-1d35935b",
"signature_type": "Line"
}
]