Ad

CVE-2025-65102

HIGH CVSS 4.0: 8.7 EPSS 0.05%
Updated Nov 22, 2025
Pjsip
Parameter Value
CVSS 8.7 (HIGH)
Fixed In 2.16
Type CWE-120 (Buffer Copy without Checking Size)
Vendor Pjsip
Public PoC No

PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the input frame as long as the decoder ptime, while the input frame length, which is based on stream ptime, may be less than that. This issue affects PJSIP users who use the Opus audio codec in receiving direction.

The vulnerability can lead to unexpected application termination due to a memory overwrite. This issue has been patched in version 2.16.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products

pjsip:pjproject