Use-after-free in pjsip - CVE-2022-23608
Published: February 24, 2022 / Updated: March 6, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in dialog set. A remote attacker can send a specially crafted request to cause a dialog set to be registered in the hash table multiple times and results in an endless loop condition.
Affected software
Debian Linux
Gentoo Linux
Ubuntu
Asterisk Open Source
Certified Asterisk
ring (Ubuntu package)
ring-daemon (Ubuntu package)
net-libs/pjproject
asterisk (Debian package)
jami (Ubuntu package)
jami-daemon (Ubuntu package)
How to mitigate CVE-2022-23608
Asterisk Open Source - addressed in versions 16.24.1, 18.10.1, 19.2.1
Certified Asterisk - update to 16.8-cert13
ring (Ubuntu package) - addressed in versions Ubuntu Pro, 20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1
ring-daemon (Ubuntu package) - addressed in versions Ubuntu Pro, 20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1
net-libs/pjproject - update to 2.12.1
asterisk (Debian package) - update to 1:16.28.0~dfsg-0+deb11u1
jami (Ubuntu package) - addressed in versions 20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1, 20230206.0~ds1-5ubuntu0.1, 20230206.0~ds2-1.3ubuntu0.1
jami-daemon (Ubuntu package) - addressed in versions 20190215.1.f152c98~ds1-1+deb10u2build0.20.04.1, 20230206.0~ds1-5ubuntu0.1, 20230206.0~ds2-1.3ubuntu0.1