CVE-2018-1000099 describes an Access of Null/Uninitialized Pointer vulnerability in Teluu PJSIP version 2.7.1 and earlier, impacting products like Debian Linux and PJSIP. This flaw allows an unauthenticated attacker to cause a denial of service (crash) by sending a specially crafted message over the network. With a CVSS v3 score of 7.5 (High), it presents a significant availability risk due to its low attack complexity and lack of user interaction required. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability was addressed in PJSIP version 2.7.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.7.1CPE matchmatch criteria | cpe:2.3:a:teluu:pjsip:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.