{"id":"CVE-2021-43845","details":"PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an out-of-bound read access. This affects all users that use PJMEDIA and RTCP XR. A malicious actor can send a RTCP XR message with an invalid packet size.","aliases":["GHSA-r374-qrwv-86hh"],"modified":"2026-07-09T10:52:20.887738Z","published":"2021-12-27T18:15:07.460Z","database_specific":{"unresolved_ranges":[{"vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10.0"},{"last_affected":"10.0"},{"introduced":"11.0"},{"last_affected":"11.0"}],"source":"CPE_STRING"}]},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00038.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00030.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/03/msg00035.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202210-37"},{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5285"},{"type":"FIX","url":"https://github.com/pjsip/pjproject/commit/f74c1fc22b760d2a24369aa72c74c4a9ab985859"},{"type":"FIX","url":"https://github.com/pjsip/pjproject/pull/2924"},{"type":"FIX","url":"https://github.com/pjsip/pjproject/security/advisories/GHSA-r374-qrwv-86hh"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pjsip/pjproject","events":[{"introduced":"0"},{"last_affected":"513700f74787009241a11eda125284277f7dfc1c"},{"fixed":"f74c1fc22b760d2a24369aa72c74c4a9ab985859"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.11.1"}]}}],"versions":["2.11.1","2.11","2.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43845.json","vanir_signatures_modified":"2026-07-09T10:52:20Z","vanir_signatures":[{"source":"https://github.com/pjsip/pjproject/commit/f74c1fc22b760d2a24369aa72c74c4a9ab985859","target":{"file":"pjmedia/src/pjmedia/rtcp_xr.c"},"deprecated":false,"digest":{"line_hashes":["4073572344689943911124658718667752297","209010379036503664911872474770178801417","171642782584085040410049896457325435756","51406099031871112102662163582770951807","101606692147499361841599617856433669746","39002042882445297833373814622502506687","93524811712521803336451275932915612712","219078617565287023457299214877517836405","93993527446036329088164087373480765830","294045389916670558896821548348881358083","164487798707190644002308488821824218494","14335266818349053158887545740262944328","216751028195986996072550307876660182928"],"threshold":0.9},"id":"CVE-2021-43845-1f9c9477","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"length":5582,"function_hash":"163415554810497209360073698107880337313"},"id":"CVE-2021-43845-8b7a2b25","signature_type":"Function","signature_version":"v1","source":"https://github.com/pjsip/pjproject/commit/f74c1fc22b760d2a24369aa72c74c4a9ab985859","target":{"file":"pjmedia/src/pjmedia/rtcp_xr.c","function":"pjmedia_rtcp_xr_rx_rtcp_xr"}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}