CVE-2017-16875: Teluu Pjsip

High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. The ioqueue component may issue a double key unregistration after an attacker initiates a socket connection with specific settings and sequences. Such double key unregistration will trigger an integer overflow, which may cause ioqueue backends to reject future key registrations.

Affected products

  • Teluu Pjsip: before 2.7.1 (fixed in 2.7.1)

Published 2017-11-17. Last modified 2026-06-17.