{"id":"CVE-2022-39244","summary":"Buffer overflow in pjlib scanner and pjmedia","details":"PJSIP is a free and open source multimedia communication library written in C. In versions of PJSIP prior to 2.13 the PJSIP parser, PJMEDIA RTP decoder, and PJMEDIA SDP parser are affeced by a buffer overflow vulnerability. Users connecting to untrusted clients are at risk. This issue has been patched and is available as commit c4d3498 in the master branch and will be included in releases 2.13 and later. Users are advised to upgrade. There are no known workarounds for this issue.","aliases":["GHSA-fq45-m3f7-3mhj"],"modified":"2026-08-18T17:25:06.992609Z","published":"2022-10-06T00:00:00Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-120"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39244.json"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00030.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39244.json"},{"type":"ADVISORY","url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-fq45-m3f7-3mhj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39244"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202210-37"},{"type":"ADVISORY","url":"https://www.debian.org/security/2023/dsa-5358"},{"type":"FIX","url":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/02/msg00029.html"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00038.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pjsip/pjproject","events":[{"introduced":"0"},{"fixed":"43c745789d291496fe1c3ed8a2c0dd6305260b32"},{"fixed":"c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae"}],"database_specific":{"cpe":"cpe:2.3:a:pjsip:pjsip:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.13"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["2.12","2.11","2.10"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-39244.json","vanir_signatures_modified":"2026-08-18T17:25:06Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"213950952685865893402811086591046062322","length":246},"id":"CVE-2022-39244-15d1cbec","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjlib-util/src/pjlib-util/scanner.c","function":"pj_scan_advance_n"}},{"target":{"function":"parse_media","file":"pjmedia/src/pjmedia/sdp.c"},"deprecated":false,"digest":{"length":1252,"function_hash":"277775521072234836038856166533747139174"},"id":"CVE-2022-39244-1b3e4567","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae"},{"deprecated":false,"digest":{"function_hash":"76224811998379349986108301584962788970","length":271},"id":"CVE-2022-39244-22c873f3","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjmedia/src/pjmedia/sdp.c","function":"parse_version"}},{"deprecated":false,"digest":{"function_hash":"290340756228809902743877323654335121187","length":447},"id":"CVE-2022-39244-277d8075","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"function":"parse_time","file":"pjmedia/src/pjmedia/sdp.c"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjlib-util/src/pjlib-util/scanner.c","function":"pj_scan_skip_line"},"deprecated":false,"digest":{"function_hash":"23551664558224120059484536565843230784","length":243},"id":"CVE-2022-39244-349b53bc"},{"digest":{"function_hash":"17761801694202566510629108924732449272","length":972},"id":"CVE-2022-39244-38bc0940","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjlib-util/src/pjlib-util/scanner.c","function":"pj_scan_get_unescape"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"function":"parse_attr","file":"pjmedia/src/pjmedia/sdp.c"},"deprecated":false,"digest":{"function_hash":"209218516335087160513334303515697136988","length":747},"id":"CVE-2022-39244-3e8a2658"},{"signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjlib-util/src/pjlib-util/scanner.c","function":"pj_scan_get_n"},"deprecated":false,"digest":{"function_hash":"255322047754160330488347732630997912650","length":306},"id":"CVE-2022-39244-503d8a48","signature_type":"Function"},{"digest":{"function_hash":"142539103784059910757417737483189360859","length":360},"id":"CVE-2022-39244-5f5b1d9e","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"function":"pj_scan_get_until_ch","file":"pjlib-util/src/pjlib-util/scanner.c"},"deprecated":false},{"source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjmedia/src/pjmedia/rtp.c"},"deprecated":false,"digest":{"line_hashes":["47373750773676932995402742375667435409","54983363385402824989958096750430322372","27038506390068480244947419159311379901","331478570899143318917891518366237074522","106932969455616251426552988640631515738","3254631862664702199848787660339926745","1465652351466083757105225431777745811","20395914321158773862880122531572455608"],"threshold":0.9},"id":"CVE-2022-39244-79a805cb","signature_type":"Line","signature_version":"v1"},{"target":{"file":"pjmedia/src/pjmedia/sdp.c","function":"parse_origin"},"deprecated":false,"digest":{"function_hash":"51268156644016074535019689550538699484","length":762},"id":"CVE-2022-39244-a3c08608","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae"},{"source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjmedia/src/pjmedia/sdp.c","function":"parse_generic_line"},"deprecated":false,"digest":{"function_hash":"14275944916941717849158187385444164039","length":286},"id":"CVE-2022-39244-a42e2212","signature_type":"Function","signature_version":"v1"},{"id":"CVE-2022-39244-a5321968","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjlib-util/src/pjlib-util/scanner.c","function":"pj_scan_get"},"deprecated":false,"digest":{"function_hash":"130619249341760856457272561668423673815","length":417}},{"id":"CVE-2022-39244-b51e8d84","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjlib-util/src/pjlib-util/scanner.c","function":"pj_scan_get_newline"},"deprecated":false,"digest":{"function_hash":"127426635791584530498748034120600612810","length":279}},{"signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjmedia/src/pjmedia/rtp.c","function":"pjmedia_rtp_decode_rtp2"},"deprecated":false,"digest":{"function_hash":"164191359095561494953798745834136139442","length":1068},"id":"CVE-2022-39244-b5fb61aa","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"259079478775090430153311955271093018147","length":427},"id":"CVE-2022-39244-b8d50689","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjlib-util/src/pjlib-util/scanner.c","function":"pj_scan_get_until_chr"}},{"id":"CVE-2022-39244-cc50ffe9","signature_type":"Line","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjmedia/src/pjmedia/sdp.c"},"deprecated":false,"digest":{"line_hashes":["50731096722935286604797726310650472956","338561032078588475275413812216106435230","271213309171260200674963233248069586702","152218875279097799920138685897116554261","146289484326140699409460390852737140079","285001491589255676387027966819732132871","219800598154808623212835385835007451060","285294197777397308708489475099825315759","62201479803257595235188374182083717440","233678380304687062322896114209683833147","48428831041996086255385308520841001758","152218875279097799920138685897116554261","321515425858408226181377942775433446775","234047520301743401670996209035642451208","239576908008899372400516822661063874686","152218875279097799920138685897116554261","12520212106394775706306525817898083641","16297401897479887591503872854253531654","214393490757306055466508655314611329728","152218875279097799920138685897116554261","112139219740848020146795759843477720238","322456647679099520425855188428739995523","213492267856999177429536143406671822861","152218875279097799920138685897116554261","25228098271380676944300384396835611760","207838881226085158134741490363180740033","180191608610857518859929853032441484678","220037672613877875863334262597925419040","169526843482778922232978704512116638962","85930411291504234405446153900953132543","92527665989903850482709870093746079233","193171517067280251852237617380735215362","113350302973147636737132474611437342271","53282097755565753081326453592164546933","210620498277428322013927194417597252018","104165423450544725124352859378204933682","175316694148813963830120914113989734421","89761159628054943340822518082151992828","209025822680022830049301922162375941165","159190488538021099306213252586481114244","247259423614306727994481623236455600311","229720256282729375325297736890554074556","239412727035837578778158009379471412206","24859887545401017910656067628400269296"],"threshold":0.9}},{"digest":{"function_hash":"188746369327872046740116037643516832326","length":382},"id":"CVE-2022-39244-cd65d4e4","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"function":"pj_scan_get_until","file":"pjlib-util/src/pjlib-util/scanner.c"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/c4d34984ec92b3d5252a7d5cddd85a1d3a8001ae","target":{"file":"pjlib-util/src/pjlib-util/scanner.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["67184227381764246987117745475422389674","1995423884440032619957311120003733794","61506189246800333176557054608242735610","114315863993261696254247136314444429597","180378914499472707330962472514323632947","319224843584854738870846004963653244631","189780298353449372917637564186680041680","130953412434086488913395454775963645798","330871944204846498925493626375799982604","194160421958184746601695039555260076394","196991214505550238823177700782406358681","75365234767513771577613450005601532865","272379999863353812359996020509245691463","59924673757053184042522784021078669917","130204493410618667523689993916451657310","265432584960296443516321721427592640050","256506683952158622013545462052174005700","236856584783266546118849472848283353237","260898158191583506815732060246974652375","109527603790689760852990704021918746057","335430463165273168200515962126591849322","238501070711644895882826401391536444692","97344857815740745856249038062167048574","178694711934876636472977502703897118476","88966391513683736110229031583540606415","214954571162139533636189652952941515304","156489262174808667436397231312311566923","155467567651343907724880807685750040972","194708337754185950111345622940237754808","72707773349697823274384842334641878403","247582314050660172101536391405688687246","155467567651343907724880807685750040972","194708337754185950111345622940237754808","72707773349697823274384842334641878403","247582314050660172101536391405688687246","155467567651343907724880807685750040972","194708337754185950111345622940237754808","72707773349697823274384842334641878403","247582314050660172101536391405688687246","64287608564294540929588103717208093225","179947070514425738344708594208914045591","96352161117062705351373736023482490953","324417149374168199339292640457267231123","212865003538080672239074563515135300791"]},"id":"CVE-2022-39244-f12d3be0"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}