Total vulnerabilities in the database
A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport at the same time that Asterisk is also performing activity on that subscription.
Software | From | Fixed in |
---|---|---|
sangoma / certified_asterisk | 18.9-cert2 | 18.9-cert2.x |
sangoma / asterisk | 19.6.0 | 19.7.1 |
sangoma / asterisk | 18.14.0 | 18.15.1 |
sangoma / asterisk | 16.0.0 | 16.29.1 |
sangoma / asterisk | 20.0.0 | 20.0.0.x |