{"id":"CVE-2021-37706","details":"PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not checked before performing a subtraction operation, potentially resulting in an integer underflow scenario. This issue affects all users that use STUN. A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s machine. Users are advised to upgrade as soon as possible. There are no known workarounds.","modified":"2026-02-24T11:40:26.920551Z","published":"2021-12-22T18:15:07.487Z","related":["GHSA-2qpg-f6wf-w984","USN-6422-2"],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00038.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00030.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/166225/Asterisk-Project-Security-Advisory-AST-2022-004.html"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2022/Mar/0"},{"type":"ADVISORY","url":"https://github.com/pjsip/pjproject/commit/15663e3f37091069b8c98a7fce680dc04bc8e865"},{"type":"ADVISORY","url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-2qpg-f6wf-w984"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/03/msg00035.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202210-37"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5285"},{"type":"FIX","url":"http://seclists.org/fulldisclosure/2022/Mar/0"},{"type":"FIX","url":"https://github.com/pjsip/pjproject/commit/15663e3f37091069b8c98a7fce680dc04bc8e865"},{"type":"FIX","url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-2qpg-f6wf-w984"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2022/Mar/0"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2022/03/msg00035.html"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"0"},{"fixed":"d436f568583184a13aa46349af5a3f0907087b44"},{"introduced":"2c1bba3cbec008c8ce35c78a2c79f9f207ea58bc"},{"fixed":"4cf4f5f7076125bc649727540de5922c21e0558f"},{"introduced":"a65908f83e2f17a3aca7eb39c8e06045aca02674"},{"fixed":"c28961a7d88cf065f693d1ea412c3e2b35e6d18e"},{"introduced":"de4f63b4824c91a0cd9f3d95f3b7923bec71960c"},{"fixed":"7eb4edc725d6fa6877d88129d7bf99c0a1604de9"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-37706.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}