Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2022-37325
HistoryDec 05, 2022 - 9:15 p.m.

CVE-2022-37325

2022-12-0521:15:10
Debian Security Bug Tracker
security-tracker.debian.org
18
sangoma
asterisk
ooh323c

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

71.7%

In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.

OSVersionArchitecturePackageVersionFilename
Debian11allasterisk< 1:16.28.0~dfsg-0+deb11u2asterisk_1:16.28.0~dfsg-0+deb11u2_all.deb
Debian999allasterisk< 1:20.0.1~dfsg+~cs6.12.40431414-1asterisk_1:20.0.1~dfsg+~cs6.12.40431414-1_all.deb

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

71.7%