CVE-2017-16872: Debian Linux

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the potential to overflow, either causing unintended values to be captured or, if the values were subsequently converted back to strings, a buffer overrun. This will lead to a potential exploit using carefully crafted invalid values.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Teluu Pjsip: before 2.7.1 (fixed in 2.7.1)

Published 2017-11-17. Last modified 2026-06-17.