CVE-2022-42706
Summary
| CVE | CVE-2022-42706 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-05 21:15:00 UTC |
| Updated | 2023-02-24 00:15:00 UTC |
| Description | An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181602 Debian Security Update for asterisk (DLA 3335-1)
- 181679 Debian Security Update for asterisk (DSA 5358-1)
- 502709 Alpine Linux Security Update for asterisk
- 510668 Alpine Linux Security Update for asterisk
- 691046 Free Berkeley Software Distribution (FreeBSD) Security Update for sterisk (8dd438ed-a338-11ed-b48b-589cfc0f81b0)