Executive brief
PJSIP is a multimedia communications library used in voice and video applications. A flaw in its AVI video file parser allows a maliciously crafted video file to write data beyond the allocated memory buffer. When an application plays such a file, an attacker can crash the process, corrupt memory, or potentially execute code.
Technical details
The AVI parser uses a chunk length field from the input file to determine how many bytes to copy into the frame buffer, without validating it against the buffer capacity derived from declared media dimensions. This heap-based buffer overflow (CWE-122, CWE-787) occurs when reading frames from a crafted AVI file. The only guard is an assertion, which is disabled in release builds; a fix clamping reads to buffer capacity and removing assertion reliance has been committed.
Affected products
- PJSIP PJSIP 2.17 and earlier
Timeline
- 2026-07-13: disclosed: GHSA-6p2p-5wf8-h5hr published
- 2026-09-18: disclosed: CVE-2026-77396 published
- 2026-07-13: patched: Fix committed to master branch (7ecc658)