CNNVD-202602-1822 Information

CNNVD ID

CNNVD-202602-1822

CVE-2026-25994

  • CNNVD Published: 2026-02-11

Description (Chinese)

PJSIP是pjsip开源的一个免费和开源的多媒体通信库,用C语言编写,实现基于标准的协议,如SIP, SDP, RTP, STUN, TURN,和ICE。 PJSIP 2.16及之前版本存在安全漏洞,该漏洞源于处理具有过长用户名的凭据时存在缓冲区溢出。

Description (English)

PJSIP is a free and open multimedia repository of pjsip open source, written in C language, to achieve standard-based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. The PJSIP 2.16 and previous versions had a security loophole, which stemmed from the spilling of the buffer zone during the processing of evidence with too long user names.

Vulnerability Type

其他

Affected Vendor

pjsip

Published

2026-02-11

Last Modified

2026-02-24

References

https://github.com/pjsip/pjproject/commit/063b3a155f163cc5a9a1df2c56b6720fd3a0dbb0 https://github.com/pjsip/pjproject/security/advisories/GHSA-j29p-pvh2-pvqp https://access.redhat.com/security/cve/cve-2026-25994

Share on: