5.9
CVSSv3

CVE-2021-32686

Published: 23/07/2021 Updated: 16/11/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP before version 2.11.1, there are a couple of issues found in the SSL socket. First, a race condition between callback and destroy, due to the accepted socket having no group lock. Second, the SSL socket parent/listener may get destroyed during handshake. Both issues were reported to happen intermittently in heavy load TLS connections. They cause a crash, resulting in a denial of service. These are fixed in version 2.11.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

teluu pjsip

debian debian linux 9.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #991931 CVE-2021-32686 / AST-2021-009: pjproject/pjsip: crash when SSL socket destroyed during handshake Package: src:asterisk; Maintainer for src:asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Reported by: Bernhard Schmidt <berni@debianorg> Date: Fri, 6 Aug 202 ...
Debian Bug report logs - #1014998 ring: CVE-2021-32686 CVE-2021-37706 CVE-2022-21723 CVE-2022-23608 CVE-2021-43299 CVE-2021-43300 CVE-2021-43301 CVE-2021-43302 CVE-2021-43303 CVE-2021-43804 CVE-2021-43845 CVE-2022-21722 CVE-2022-24754 CVE-2022-24763 CVE-2022-24764 CVE-2022-24793 Package: src:ring; Maintainer for src:ring is Debian VoIP Te ...
Multiple vulnerabilities have been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in denial of service For the stable distribution (bullseye), these problems have been fixed in version 1:16161~dfsg-1+deb11u1 We recommend that you upgrade your asterisk packages For the detailed security status of asterisk ple ...

Mailing Lists

Asterisk Project Security Advisory - AST-2021-009 Product Asterisk Summary pjproject/pjsip: crash when SSL socket destroyed during handshake Nature of Advisory Denial of service ...