CVE-2022-31002: Debian Linux

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, an attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. This type of crash may be caused by a URL ending with `%`. Version 1.13.8 contains a patch for this issue.

Affected products

  • Debian Debian Linux: version 10.0 only
  • Signalwire Sofia-SIP: before 1.13.8 (fixed in 1.13.8)

Published 2022-05-31. Last modified 2026-06-17.