CVE-2018-1000099: Debian Linux

High severity, CVSS 7.5. EPSS: 3.4% chance of exploitation in the next 30 days.

Teluu PJSIP version 2.7.1 and earlier contains a Access of Null/Uninitialized Pointer vulnerability in pjmedia SDP parsing that can result in Crash. This attack appear to be exploitable via Sending a specially crafted message. This vulnerability appears to have been fixed in 2.7.2.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Teluu Pjsip: up to and including 2.7.1

Published 2018-03-13. Last modified 2026-06-17.