PT-2022-23927 · Sangoma+1 · Asterisk+1

Published

2020-07-06

·

Updated

2023-02-24

·

CVE-2022-37325

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Sangoma Asterisk versions 16.28.0 and earlier, 17.x, 18.x through 18.14.0, and 19.x through 19.6.0
Description The issue arises from an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE, which can cause a crash.
Recommendations For versions 16.28.0 and earlier, 17.x, 18.x through 18.14.0, and 19.x through 19.6.0, consider updating to a version later than 19.6.0 to resolve the issue. As a temporary workaround, consider restricting access to the ooq931.c file in the addons/ooh323c/src directory until a patch is available. Avoid processing incoming Setup messages with malformed Calling or Called Party IE in the affected ooq931.c file until the issue is resolved.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2313
CVE-2022-37325
DLA-3335-1
DSA-5358-1

Affected Products

Alt Linux
Asterisk