CVE-2026-77396: CWE-122: Heap-based Buffer Overflow in pjsip pjproject
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into a frame buffer whose capacity is derived from the declared media dimensions. A crafted AVI file can therefore cause an attacker-controlled out-of-bounds write past the heap allocation when an application plays the file or pulls its frames. The existing size assertion does not protect production release builds, where assertions are disabled. Typical local playback can crash the process, while applications that accept untrusted AVI sources expose a stronger memory-corruption condition. No fixed version is available as of this review.
AI Analysis
Technical Summary
PJSIP pjproject versions 2.17 and earlier contain a heap-based buffer overflow in the AVI parser located in pjmedia/src/pjmedia/avi_player.c. The vulnerability arises because the parser uses the video chunk length from an input AVI file as the number of bytes copied into a frame buffer, whose size is based on declared media dimensions. Since production builds disable assertions that would otherwise check size constraints, a crafted AVI file can trigger an out-of-bounds write on the heap. This can lead to process crashes during local playback or more severe memory corruption when untrusted AVI sources are accepted by applications.
Potential Impact
Exploitation of this vulnerability can cause application crashes or memory corruption, potentially leading to denial of service or other undefined behavior. The vulnerability requires local or user interaction (playing or processing a crafted AVI file). There are no known exploits in the wild. The CVSS 4.0 score is 6.9 (medium severity), reflecting the local attack vector and high impact on integrity and availability.
Mitigation Recommendations
No official patch or fixed version is currently available. Users should avoid processing untrusted AVI files with affected versions of pjproject. Monitor vendor advisories for updates or patches. Since assertions are disabled in production builds, relying on them is not sufficient mitigation.
CVE-2026-77396: CWE-122: Heap-based Buffer Overflow in pjsip pjproject
Description
PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into a frame buffer whose capacity is derived from the declared media dimensions. A crafted AVI file can therefore cause an attacker-controlled out-of-bounds write past the heap allocation when an application plays the file or pulls its frames. The existing size assertion does not protect production release builds, where assertions are disabled. Typical local playback can crash the process, while applications that accept untrusted AVI sources expose a stronger memory-corruption condition. No fixed version is available as of this review.
CVSS v4.0
Score 6.9medium
Affected software
pjsip
pjproject
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
PJSIP pjproject versions 2.17 and earlier contain a heap-based buffer overflow in the AVI parser located in pjmedia/src/pjmedia/avi_player.c. The vulnerability arises because the parser uses the video chunk length from an input AVI file as the number of bytes copied into a frame buffer, whose size is based on declared media dimensions. Since production builds disable assertions that would otherwise check size constraints, a crafted AVI file can trigger an out-of-bounds write on the heap. This can lead to process crashes during local playback or more severe memory corruption when untrusted AVI sources are accepted by applications.
Potential Impact
Exploitation of this vulnerability can cause application crashes or memory corruption, potentially leading to denial of service or other undefined behavior. The vulnerability requires local or user interaction (playing or processing a crafted AVI file). There are no known exploits in the wild. The CVSS 4.0 score is 6.9 (medium severity), reflecting the local attack vector and high impact on integrity and availability.
Mitigation Recommendations
No official patch or fixed version is currently available. Users should avoid processing untrusted AVI files with affected versions of pjproject. Monitor vendor advisories for updates or patches. Since assertions are disabled in production builds, relying on them is not sufficient mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-20T19:55:27.023Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aad759f55bf5e2cf54f35d4
Added to database: 09/18/2026, 17:32:15 UTC
Last enriched: 09/18/2026, 17:47:02 UTC
Last updated: 09/19/2026, 01:56:09 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.