7.8

CVE-2026-23740

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files to a directory that is world-writable (for example /tmp), an attacker with write permission(which is all users on a linux system) to that directory can cause root to execute arbitrary commands or overwrite arbitrary files by controlling the gdb init file and output paths. This issue has been patched in versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SangomaCertified Asterisk Version13.13.0 Update-
SangomaCertified Asterisk Version13.13.0 Updatecert1
SangomaCertified Asterisk Version13.13.0 Updatecert1-rc1
SangomaCertified Asterisk Version13.13.0 Updatecert1-rc2
SangomaCertified Asterisk Version13.13.0 Updatecert1-rc3
SangomaCertified Asterisk Version13.13.0 Updatecert1-rc4
SangomaCertified Asterisk Version13.13.0 Updatecert2
SangomaCertified Asterisk Version13.13.0 Updatecert3
SangomaCertified Asterisk Version13.13.0 Updaterc1
SangomaCertified Asterisk Version13.13.0 Updaterc2
SangomaCertified Asterisk Version16.8 Updatecert1-rc1
SangomaCertified Asterisk Version16.8 Updatecert1-rc2
SangomaCertified Asterisk Version16.8 Updatecert1-rc3
SangomaCertified Asterisk Version16.8 Updatecert1-rc4
SangomaCertified Asterisk Version16.8 Updatecert1-rc5
SangomaCertified Asterisk Version16.8 Updatecert10
SangomaCertified Asterisk Version16.8 Updatecert11
SangomaCertified Asterisk Version16.8 Updatecert12
SangomaCertified Asterisk Version16.8 Updatecert13
SangomaCertified Asterisk Version16.8 Updatecert14
SangomaCertified Asterisk Version16.8 Updatecert4-rc1
SangomaCertified Asterisk Version16.8 Updatecert4-rc2
SangomaCertified Asterisk Version16.8 Updatecert4-rc3
SangomaCertified Asterisk Version16.8 Updatecert4-rc4
SangomaCertified Asterisk Version16.8.0 Update-
SangomaCertified Asterisk Version16.8.0 Updatecert1
SangomaCertified Asterisk Version16.8.0 Updatecert10
SangomaCertified Asterisk Version16.8.0 Updatecert11
SangomaCertified Asterisk Version16.8.0 Updatecert12
SangomaCertified Asterisk Version16.8.0 Updatecert2
SangomaCertified Asterisk Version16.8.0 Updatecert3
SangomaCertified Asterisk Version16.8.0 Updatecert4
SangomaCertified Asterisk Version16.8.0 Updatecert5
SangomaCertified Asterisk Version16.8.0 Updatecert6
SangomaCertified Asterisk Version16.8.0 Updatecert7
SangomaCertified Asterisk Version16.8.0 Updatecert8
SangomaCertified Asterisk Version16.8.0 Updatecert9
SangomaCertified Asterisk Version18.9 Update-
SangomaCertified Asterisk Version18.9 Updatecert1
SangomaCertified Asterisk Version18.9 Updatecert1-rc1
SangomaCertified Asterisk Version18.9 Updatecert10
SangomaCertified Asterisk Version18.9 Updatecert11
SangomaCertified Asterisk Version18.9 Updatecert12
SangomaCertified Asterisk Version18.9 Updatecert13
SangomaCertified Asterisk Version18.9 Updatecert14
SangomaCertified Asterisk Version18.9 Updatecert15
SangomaCertified Asterisk Version18.9 Updatecert16
SangomaCertified Asterisk Version18.9 Updatecert2
SangomaCertified Asterisk Version18.9 Updatecert3
SangomaCertified Asterisk Version18.9 Updatecert4
SangomaCertified Asterisk Version18.9 Updatecert5
SangomaCertified Asterisk Version18.9 Updatecert6
SangomaCertified Asterisk Version18.9 Updatecert7
SangomaCertified Asterisk Version18.9 Updatecert8
SangomaCertified Asterisk Version18.9 Updatecert8-rc1
SangomaCertified Asterisk Version18.9 Updatecert8-rc2
SangomaCertified Asterisk Version18.9 Updatecert9
SangomaCertified Asterisk Version20.7 Updatecert1
SangomaCertified Asterisk Version20.7 Updatecert1-rc1
SangomaCertified Asterisk Version20.7 Updatecert1-rc2
SangomaCertified Asterisk Version20.7 Updatecert2
SangomaCertified Asterisk Version20.7 Updatecert3
SangomaCertified Asterisk Version20.7 Updatecert4
SangomaCertified Asterisk Version20.7 Updatecert5
SangomaCertified Asterisk Version20.7 Updatecert6
SangomaCertified Asterisk Version20.7 Updatecert7
SangomaAsterisk Version < 20.18.2
SangomaAsterisk Version >= 21.0.0 < 21.12.1
SangomaAsterisk Version >= 22.0.0 < 22.8.2
SangomaAsterisk Version >= 23.0.0 < 23.2.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.02% 0.047
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
security-advisories@github.com 0 1.8 0
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:N
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.