CVE-2022-26651
15.04.2022, 05:15
An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly a SQL injection. This is fixed in 16.25.2, 18.11.2, and 19.3.2, and 16.8-cert14.
Vendor | Product | Version |
---|---|---|
digium | asterisk | 16.0.0 ≤ 𝑥 < 16.25.2 |
digium | asterisk | 18.0 ≤ 𝑥 < 18.11.2 |
digium | asterisk | 19.0.0 ≤ 𝑥 < 19.3.2 |
digium | certified_asterisk | 16.8 |
digium | certified_asterisk | 16.8:cert1-rc1 |
digium | certified_asterisk | 16.8:cert1-rc2 |
digium | certified_asterisk | 16.8:cert1-rc3 |
digium | certified_asterisk | 16.8:cert1-rc4 |
digium | certified_asterisk | 16.8:cert10 |
digium | certified_asterisk | 16.8:cert11 |
digium | certified_asterisk | 16.8:cert12 |
digium | certified_asterisk | 16.8:cert13 |
digium | certified_asterisk | 16.8:cert2 |
digium | certified_asterisk | 16.8:cert3 |
digium | certified_asterisk | 16.8:cert4 |
digium | certified_asterisk | 16.8:cert4-rc1 |
digium | certified_asterisk | 16.8:cert4-rc2 |
digium | certified_asterisk | 16.8:cert4-rc3 |
digium | certified_asterisk | 16.8:cert4-rc4 |
digium | certified_asterisk | 16.8:cert5 |
digium | certified_asterisk | 16.8:cert6 |
digium | certified_asterisk | 16.8:cert7 |
digium | certified_asterisk | 16.8:cert8 |
digium | certified_asterisk | 16.8:cert9 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References