CVE-2022-26498
Summary
| CVE | CVE-2022-26498 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-15 05:15:00 UTC |
| Updated | 2023-05-04 17:15:00 UTC |
| Description | An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not certificates. These files could be much larger than what one would expect to download, leading to Resource Exhaustion. This is fixed in 16.25.2, 18.11.2, and 19.3.2. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181225 Debian Security Update for asterisk (DLA 3194-1)
- 181237 Debian Security Update for asterisk (DSA 5285-1)
- 502207 Alpine Linux Security Update for asterisk
- 503867 Alpine Linux Security Update for asterisk
- 690843 Free Berkeley Software Distribution (FreeBSD) Security Update for asterisk (8838abf0-bc47-11ec-b516-0897988a1c07)