PT-2022-23927 · Sangoma+1 · Asterisk+1
Published
2020-07-06
·
Updated
2023-02-24
·
CVE-2022-37325
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Sangoma Asterisk versions 16.28.0 and earlier, 17.x, 18.x through 18.14.0, and 19.x through 19.6.0
Description
The issue arises from an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE, which can cause a crash.
Recommendations
For versions 16.28.0 and earlier, 17.x, 18.x through 18.14.0, and 19.x through 19.6.0, consider updating to a version later than 19.6.0 to resolve the issue.
As a temporary workaround, consider restricting access to the ooq931.c file in the addons/ooh323c/src directory until a patch is available.
Avoid processing incoming Setup messages with malformed Calling or Called Party IE in the affected ooq931.c file until the issue is resolved.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Asterisk