Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-37325
HistoryDec 05, 2022 - 12:00 a.m.

CVE-2022-37325

2022-12-0500:00:00
ubuntu.com
ubuntu.com
15
sangoma
asterisk
vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

71.7%

In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and
19.x through 19.6.0, an incoming Setup message to
addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can
cause a crash.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

71.7%