NA

CVE-2022-42705

Published: 05/12/2022 Updated: 24/02/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated malicious user to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport at the same time that Asterisk is also performing activity on that subscription.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sangoma certified asterisk 18.9

sangoma asterisk

sangoma asterisk 20.0.0

Vendor Advisories

Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange Buffer overflows and other programming errors could be exploited for launching a denial of service attack or the execution of arbitrary code For the stable distribution (bullseye), these problems have been fixed in version 1:16280~dfsg-0+d ...