Search CVE reports


Toggle filters

21 – 30 of 189 results


CVE-2022-23537

Medium priority

Some fixes available 2 of 11

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. Buffer overread is possible when parsing a specially crafted...

4 affected packages

asterisk, pjproject, ring, sip

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Vulnerable Not affected Not affected
pjproject Not in release Not in release Vulnerable
ring Not in release Not in release Fixed Fixed
sip Not in release Not in release Not in release
Show less packages

CVE-2022-42706

Medium priority
Needs evaluation

An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-42705

Medium priority
Needs evaluation

A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-37325

Medium priority
Needs evaluation

In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-39269

Medium priority
Vulnerable

PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media...

3 affected packages

asterisk, pjproject, ring

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Ignored Ignored
pjproject Not in release Not in release Vulnerable
ring Not in release Not in release Ignored Ignored
Show less packages

CVE-2022-39244

Medium priority

Some fixes available 2 of 12

PJSIP is a free and open source multimedia communication library written in C. In versions of PJSIP prior to 2.13 the PJSIP parser, PJMEDIA RTP decoder, and PJMEDIA SDP parser are affeced by a buffer overflow vulnerability. Users...

3 affected packages

asterisk, pjproject, ring

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Ignored Ignored
pjproject Not in release Not in release Vulnerable
ring Not in release Not in release Fixed Fixed
Show less packages

CVE-2021-46837

Medium priority
Needs evaluation

res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asterisk before 16.8-cert7, allows an attacker to trigger a crash by sending an m=image line and zero port in...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Not affected Not affected Needs evaluation Needs evaluation
Show less packages

CVE-2022-24792

Medium priority
Vulnerable

PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV files. The...

3 affected packages

asterisk, pjproject, ring

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Ignored Ignored
pjproject Vulnerable
ring Not in release Ignored Ignored
Show less packages

CVE-2022-26651

Medium priority
Needs evaluation

An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-26499

Medium priority
Needs evaluation

An SSRF issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it's possible to send arbitrary requests (such as GET) to interfaces such as localhost by using the Identity header. This is fixed in 16.25.2, 18.11.2,...

1 affected package

asterisk

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
asterisk Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages