
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through version 0.10.0. The vulnerability exists in the janus_get_codec_from_pt function in utils.c, which contains a Buffer Overflow vulnerability that can be triggered via a long value in an SDP Offer packet (NVD).
The vulnerability is related to improper usage of sscanf in the janus_get_codec_from_pt function within utils.c. The issue was discovered by Marat Gayanov at Digital Security (dsec.ru) and was assigned a CVSS v3.1 score of 9.8 (CRITICAL) (NVD, GitHub PR).
The buffer overflow vulnerability could potentially allow an attacker to execute arbitrary code or cause a denial of service condition through a specially crafted SDP Offer packet (NVD).
The vulnerability can be exploited by sending a maliciously crafted SDP Offer packet containing a long value to the affected Janus WebRTC Server (NVD).
The issue was fixed in a security update. Users should upgrade to a version of Janus WebRTC Server that contains the fix. The fix involved addressing the improper usage of sscanf in the affected code (GitHub PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."