9.8

CVE-2022-23608

Use after free in PJSIP

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by multiple UAC dialogs can potentially be prematurely freed when one of the dialogs is destroyed . The issue may cause a dialog set to be registered in the hash table multiple times (with different hash keys) leading to undefined behavior such as dialog list collision which eventually leading to endless loop. A patch is available in commit db3235953baa56d2fb0e276ca510fefca751643f which will be included in the next release. There are no known workarounds for this issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Teluu ≫ Pjsip Version <= 2.11.1
Asterisk ≫ Certified Asterisk Version < 16.8.0
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert1
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert10
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert11
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert12
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert2
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert3
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert4
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert5
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert6
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert7
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert8
Asterisk ≫ Certified Asterisk Version 16.8.0 Update cert9
Sangoma ≫ Asterisk Version >= 16.0.0 < 16.24.1
Sangoma ≫ Asterisk Version >= 18.0.0 < 18.10.1
Sangoma ≫ Asterisk Version >= 19.0.0 < 19.2.1
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.06% 0.895
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
security-advisories@github.com 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

https://lists.debian.org/debian-lts-announce/2022/03/msg00035.html
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/202210-37
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2022/11/msg00021.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2023/08/msg00038.html
https://www.debian.org/security/2022/dsa-5285
Third Party Advisory
http://packetstormsecurity.com/files/166226/Asterisk-Project-Security-Advisory-AST-2022-005.html
Third Party Advisory
VDB Entry
http://seclists.org/fulldisclosure/2022/Mar/1
Patch
Third Party Advisory
Mailing List
https://github.com/pjsip/pjproject/commit/db3235953baa56d2fb0e276ca510fefca751643f
Patch
Third Party Advisory
https://github.com/pjsip/pjproject/security/advisories/GHSA-ffff-m5fm-qm62
Patch
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2022/03/msg00040.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2024/09/msg00030.html