Home / Companies / JFrog / Blog / Post Details
Content Deep Dive

JFrog Discloses 5 Memory Corruption Vulnerabilities in PJSIP – A Popular Multimedia Library

Blog post from JFrog

Post Details
Company
Date Published
Author
Uriya Yavniely
Word Count
1,122
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

JFrog's Security Research team uncovered five security vulnerabilities in PJSIP, an open-source multimedia communication library used by applications like WhatsApp and Asterisk. These vulnerabilities, which include stack overflows and buffer overflows, can lead to arbitrary code execution or denial of service when exploited. The affected functions include pjsua_player_create, pjsua_recorder_create, pjsua_playlist_create, and pjsua_call_dump, with risks contingent on passing attacker-controlled arguments. Although JFrog disclosed these vulnerabilities to PJSIP's maintainers, they have not identified any specific vulnerable applications. Users are advised to upgrade to PJSIP version 2.12 to address these issues, and JFrog's Xray SCA tool provides automated security scanning to identify such vulnerabilities.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.