Critical PJSIP Vulnerabilities Affecting Ubuntu 16.04 and 18.04 LTS

Critical PJSIP Vulnerabilities Affecting Ubuntu 16.04 and 18.04 LTS

First seen 25 Mar 2026, 02:46 UTC UbuntuLinuxsecurity 72.0

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities in the PJSIP library have been identified, affecting Ubuntu 16.04 and 18.04 LTS. Youngsung Kim discovered a flaw that allows remote attackers to crash PJSIP by improperly parsing numeric header fields in SIP messages (CVE-2017-16872). Peter Koletzki found another vulnerability that could lead to denial of service by mishandling connection requests (CVE-2017-16875). Additionally, other issues were reported that could also cause crashes or denial of service. These vulnerabilities primarily impact Ubuntu 16.04 LTS, with some implications for Ubuntu 18.04 LTS. Users are advised to update to the latest package versions to mitigate these risks. The vulnerabilities could allow attackers to execute arbitrary code or disrupt services, emphasizing the need for immediate action.

Key Points: • PJSIP vulnerabilities could lead to denial of service or arbitrary code execution. • Affected systems include Ubuntu 16.04 and 18.04 LTS. • Immediate updates are recommended to mitigate these vulnerabilities.

Timeline

2017-11-17
CVE-2017-16872 and CVE-2017-16875 published
2018-03-13
CVE-2018-1000099 published
2018-03-13
CVE-2018-1000098 published
2021-03-10
CVE-2020-15260 published
2021-03-10
CVE-2021-21375 published
2021-07-23
CVE-2021-32686 published
2021-12-22
CVE-2021-37706 published
2022-02-16
CVE-2021-43299 published
2022-02-16
CVE-2021-43303 published
2022-02-16
CVE-2021-43302 published