Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
PJSIP's pjmedia-video has use-after-free in H264 packetizer when packetizing fragmented NAL
Vulnerability Description
PJSIP is a free and open source multimedia communication library. Versions prior to 2.17 have a critical heap buffer underflow vulnerability in PJSIP's H.264 packetizer. The bug occurs when processing malformed H.264 bitstreams without NAL unit start codes, where the packetizer performs unchecked pointer arithmetic that can read from memory located before the allocated buffer. Version 2.17 contains a patch for the issue.
CVSS Information
N/A
Vulnerability Type
释放后使用
Vulnerability Title
PJSIP 资源管理错误漏洞
Vulnerability Description
PJSIP是pjsip开源的一个免费和开源的多媒体通信库,用C语言编写,实现基于标准的协议,如SIP, SDP, RTP, STUN, TURN,和ICE。 PJSIP 2.17之前版本存在资源管理错误漏洞,该漏洞源于H.264分组器在处理畸形H.264比特流时存在堆缓冲区下溢,可能导致从分配缓冲区之前的内存读取数据。
CVSS Information
N/A
Vulnerability Type
N/A