Vulnerability Details CVE-2022-42705
A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport at the same time that Asterisk is also performing activity on that subscription.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.6%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2022-42705
-
cpe:2.3:a:sangoma:asterisk:16.0.0
-
cpe:2.3:a:sangoma:asterisk:16.10.0
-
cpe:2.3:a:sangoma:asterisk:16.11.0
-
cpe:2.3:a:sangoma:asterisk:16.12.0
-
cpe:2.3:a:sangoma:asterisk:16.14.0
-
cpe:2.3:a:sangoma:asterisk:16.14.1
-
cpe:2.3:a:sangoma:asterisk:16.15.0
-
cpe:2.3:a:sangoma:asterisk:16.16.0
-
cpe:2.3:a:sangoma:asterisk:16.16.1
-
cpe:2.3:a:sangoma:asterisk:16.5.0
-
cpe:2.3:a:sangoma:asterisk:16.6.0
-
cpe:2.3:a:sangoma:asterisk:16.7.0
-
cpe:2.3:a:sangoma:asterisk:16.8.0
-
cpe:2.3:a:sangoma:asterisk:16.9.0
-
cpe:2.3:a:sangoma:asterisk:18.14.0
-
cpe:2.3:a:sangoma:asterisk:18.15.0
-
cpe:2.3:a:sangoma:asterisk:19.6.0
-
cpe:2.3:a:sangoma:asterisk:19.7.0
-
cpe:2.3:a:sangoma:asterisk:20.0.0
-
cpe:2.3:a:sangoma:certified_asterisk:18.9