Teluu PJSIP version 2.7.1 and earlier contains a Access of Null/Uninitialized Pointer vulnerability in pjmedia SDP parsing that can result in Crash. This attack appear to be exploitable via Sending a specially crafted message. This vulnerability appears to have been fixed in 2.7.2.
{
"binaries": [
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpj2"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjlib-util2"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjmedia-audiodev2"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjmedia-codec2"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjmedia-videodev2"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjmedia2"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjnath2"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjproject-dev"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjsip-simple2"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjsip-ua2"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjsip2"
},
{
"binary_version": "2.1.0.0.ast20130823-1+deb8u1build0.16.04.1",
"binary_name": "libpjsua2"
}
]
}