#VU69827 Use-after-free in Asterisk Open Source and Certified Asterisk - CVE-2022-42705
Published: December 2, 2022
Asterisk Open Source
Certified Asterisk
Digium (Linux Support Services)
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error within res_pjsip_pubsub.c, res_pjsip_outbound_registration.c, pjsip_transport_events.c files when performing activity on a subscription via a reliable transport at the same time Asterisk is also performing activty on that subscription. A remote user can trigger a use-after-free error and perform a denial of service (DoS) attack.