Improper Locking Affecting pjproject package, versions <2.5.5~dfsg-6+deb9u3


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.51% (77th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN9-PJPROJECT-2331761
  • published8 Jan 2022
  • disclosed4 Jan 2022

Introduced: 4 Jan 2022

CVE-2021-41141  (opens in a new tab)
CWE-667  (opens in a new tab)

How to fix?

Upgrade Debian:9 pjproject to version 2.5.5~dfsg-6+deb9u3 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream pjproject package and not the pjproject package as distributed by Debian. See How to fix? for Debian:9 relevant fixed versions and status.

PJSIP is a free and open source multimedia communication library written in the C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In various parts of PJSIP, when error/failure occurs, it is found that the function returns without releasing the currently held locks. This could result in a system deadlock, which cause a denial of service for the users. No release has yet been made which contains the linked fix commit. All versions up to an including 2.11.1 are affected. Users may need to manually apply the patch.

CVSS Scores

version 3.1