Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-27585
Description:PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versions 2.13 and prior affects applications that use PJSIP DNS resolver. It doesn't affect PJSIP users who do not utilise PJSIP DNS resolver. This vulnerability is related to CVE-2022-24793. The difference is that this issue is in parsing the query record `parse_query()`, while the issue in CVE-2022-24793 is in `parse_rr()`. A patch is available as commit `d1c5e4d` in the `master` branch. A workaround is to disable DNS resolution in PJSIP config (by setting `nameserver_count` to zero) or use an external resolver implementation instead.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2023.3394   1.3.6.1.4.1.25623.1.1.1.1.2023.5438  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-27585
Debian Security Information: DSA-5438 (Google Search)
https://www.debian.org/security/2023/dsa-5438
https://github.com/pjsip/pjproject/commit/d1c5e4da5bae7f220bc30719888bb389c905c0c5
https://github.com/pjsip/pjproject/commit/d1c5e4da5bae7f220bc30719888bb389c905c0c5
https://github.com/pjsip/pjproject/security/advisories/GHSA-p6g5-v97c-w5q4
https://github.com/pjsip/pjproject/security/advisories/GHSA-p6g5-v97c-w5q4
https://github.com/pjsip/pjproject/security/advisories/GHSA-q9cp-8wcq-7pfr
https://github.com/pjsip/pjproject/security/advisories/GHSA-q9cp-8wcq-7pfr
https://www.pjsip.org/pjlib-util/docs/html/group__PJ__DNS__RESOLVER.htm
https://www.pjsip.org/pjlib-util/docs/html/group__PJ__DNS__RESOLVER.htm
https://lists.debian.org/debian-lts-announce/2023/04/msg00020.html
https://lists.debian.org/debian-lts-announce/2023/08/msg00038.html




© 1998-2025 E-Soft Inc. All rights reserved.