Integer underflow in Asterisk Open Source and Certified Asterisk - CVE-2022-37325
Published: December 2, 2022
Vulnerability identifier: #VU69829
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-37325
CWE-ID: CWE-191
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an integer underflow within the ooh323 module. A remote non-authenticated attacker can initiate a call with a zero length called or calling party number, trigger an integer underflow and crash Asterisk.
Affected software
Asterisk Open Source
Certified Asterisk
Debian Linux
asterisk (Debian package)
Certified Asterisk
Debian Linux
asterisk (Debian package)
How to mitigate CVE-2022-37325
Install updates from vendor's website.
Asterisk Open Source - addressed in versions 16.29.1, 18.15.1, 19.7.1, 20.0.1
Certified Asterisk - update to 18.9-cert3
asterisk (Debian package) - update to 1:16.28.0~dfsg-0+deb11u2
Certified Asterisk - update to 18.9-cert3
asterisk (Debian package) - update to 1:16.28.0~dfsg-0+deb11u2