CVE-2022-42705
Debian Security Advisory 5358-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport at the same time that Asterisk is also performing activity on that subscription.
Un use after free en res_pjsip_pubsub.c en Sangoma Asterisk 16.28, 18.14, 19.6 y certificado/18.9-cert2 puede permitir que un atacante remoto autenticado bloquee Asterisk (denegación de servicio) al realizar actividad en una suscripción a través de un transporte confiable en al mismo tiempo que Asterisk también realiza actividad en esa suscripción.
Multiple security vulnerabilities have been discovered in Asterisk, an Open Source Private Branch Exchange. Buffer overflows and other programming errors could be exploited for launching a denial of service attack or the execution of arbitrary code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-10 CVE Reserved
- 2022-12-05 CVE Published
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-416: Use After Free
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2023/02/msg00029.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://downloads.asterisk.org/pub/security/AST-2022-008.html | 2023-02-24 |
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2023/dsa-5358 | 2023-02-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sangoma Search vendor "Sangoma" | Asterisk Search vendor "Sangoma" for product "Asterisk" | >= 16.0.0 < 16.29.1 Search vendor "Sangoma" for product "Asterisk" and version " >= 16.0.0 < 16.29.1" | - |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Asterisk Search vendor "Sangoma" for product "Asterisk" | >= 18.14.0 < 18.15.1 Search vendor "Sangoma" for product "Asterisk" and version " >= 18.14.0 < 18.15.1" | - |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Asterisk Search vendor "Sangoma" for product "Asterisk" | >= 19.6.0 < 19.7.1 Search vendor "Sangoma" for product "Asterisk" and version " >= 19.6.0 < 19.7.1" | - |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Asterisk Search vendor "Sangoma" for product "Asterisk" | 20.0.0 Search vendor "Sangoma" for product "Asterisk" and version "20.0.0" | - |
Affected
| ||||||
Sangoma Search vendor "Sangoma" | Certified Asterisk Search vendor "Sangoma" for product "Certified Asterisk" | 18.9 Search vendor "Sangoma" for product "Certified Asterisk" and version "18.9" | cert2 |
Affected
|