CVE-2022-26498
Shannon Baseband chatroom SDP Attribute Memory Corruption
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Resource Exhaustion. This is fixed in 16.25.2, 18.11.2, and 19.3.2.
Se ha detectado un problema en Asterisk versiones hasta 19.x. Cuando es usado STIR/SHAKEN, es posible descargar archivos que no son certificados. Estos archivos podían ser mucho más grandes de lo que se esperaba descargar, conllevando a un agotamiento de recursos. Esto ha sido corregido en versiones 16.25.2, 18.11.2 y 19.3.2
Shannon Baseband suffers from a memory corruption vulnerability that occurs when the baseband modem processes SDP when setting up a call. SDP supports an attribute chatroom that allows multiple chat properties to be specified. The baseband software allocates a fixed-size buffer for these types, but does not check that the number of properties specified by the SDP is within this bound. This can lead to memory corruption when processing a chatroom attribute that contains more than 12 format types.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-06 CVE Reserved
- 2022-04-15 CVE Published
- 2024-08-03 CVE Updated
- 2024-11-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-400: Uncontrolled Resource Consumption
CAPEC
References (6)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/166744/Asterisk-Project-Security-Advisory-AST-2022-001.html | 2023-05-04 | |
https://downloads.asterisk.org/pub/security/AST-2022-001.html | 2023-05-04 |
URL | Date | SRC |
---|---|---|
https://downloads.asterisk.org/pub/security | 2023-05-04 | |
https://www.debian.org/security/2022/dsa-5285 | 2023-05-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | >= 16.15.0 <= 16.25.1 Search vendor "Digium" for product "Asterisk" and version " >= 16.15.0 <= 16.25.1" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | >= 18.0 < 18.11.2 Search vendor "Digium" for product "Asterisk" and version " >= 18.0 < 18.11.2" | - |
Affected
| ||||||
Digium Search vendor "Digium" | Asterisk Search vendor "Digium" for product "Asterisk" | >= 19.0.0 <= 19.3.1 Search vendor "Digium" for product "Asterisk" and version " >= 19.0.0 <= 19.3.1" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
|