Skip to content

Potential media transport downgrade from the secure version (SRTP) to the non-secure one (RTP)

Critical
sauwming published GHSA-wx5m-cj97-4wwg Oct 6, 2022

Package

No package listed

Affected versions

from 2.11 until 2.12.1

Patched versions

2.13 or later

Description

When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media to be sent insecurely.

Impact

The vulnerability impacts all PJSIP users that use SRTP.

Patches

The patch is available as commit d2acb9a in the master branch.

For more information

If you have any questions or comments about this advisory:
Email us at security@pjsip.org

Severity

Critical

CVE ID

CVE-2022-39269

Weaknesses

No CWEs

Credits