Out-of-bounds Read The advisory has been revoked - it doesn't affect any version of package pjproject  (opens in a new tab)


Threat Intelligence

EPSS
4.48% (91st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1604-PJPROJECT-2400874
  • published21 Mar 2026
  • disclosed27 Jan 2022

Introduced: 27 Jan 2022

CVE-2022-21723  (opens in a new tab)
CWE-125  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:16.04.

NVD Description

Note: Versions mentioned in the description apply only to the upstream pjproject package and not the pjproject package as distributed by Ubuntu.

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the master branch. There are no known workarounds.