CVE-2022-42705: Use After Free
A use-after-free in respjsippubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport at the same time that Asterisk is also performing activity on that subscription.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-42705?
CVE-2022-42705 is a use-after-free vulnerability in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2.
How does CVE-2022-42705 affect Sangoma Asterisk?
CVE-2022-42705 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport at the same time that Asterisk is also performing operations on the same subscription.
Which versions of Sangoma Asterisk are affected by CVE-2022-42705?
Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 are affected by CVE-2022-42705.
How can I mitigate the impact of CVE-2022-42705?
To mitigate the impact of CVE-2022-42705, it is recommended to update Sangoma Asterisk to the patched versions provided by the vendor.
Where can I find more information about CVE-2022-42705?
You can find more information about CVE-2022-42705 on the official Asterisk issue tracker (JIRA), the Asterisk security advisory, and the Asterisk Git repository.