CVE-2010-0441
Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP…
Does this matter?
Lower severity and a low EPSS score (3.38%). Track it; it rarely justifies an emergency change on its own.
Description
Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 3.38% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- asterisk/asterisk
- Source
- cve@mitre.org
References
- http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.0.diffPatch
- http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.1.diffPatch
- http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.2.diff
- http://downloads.asterisk.org/pub/security/AST-2010-001.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037679.html
- http://secunia.com/advisories/38395Vendor Advisory
- http://secunia.com/advisories/39096
- http://securitytracker.com/id?1023532
- http://www.securityfocus.com/archive/1/509327/100/0/threaded
- http://www.securityfocus.com/bid/38047
- http://www.vupen.com/english/advisories/2010/0289Vendor Advisory
- https://issues.asterisk.org/view.php?id=16517
- https://issues.asterisk.org/view.php?id=16634
- https://issues.asterisk.org/view.php?id=16724
- http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.0.diffPatch
- http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.1.diffPatch
- http://downloads.asterisk.org/pub/security/AST-2010-001-1.6.2.diff
- http://downloads.asterisk.org/pub/security/AST-2010-001.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037679.html
- http://secunia.com/advisories/38395Vendor Advisory
- http://secunia.com/advisories/39096
- http://securitytracker.com/id?1023532
- http://www.securityfocus.com/archive/1/509327/100/0/threaded
- http://www.securityfocus.com/bid/38047
- http://www.vupen.com/english/advisories/2010/0289Vendor Advisory
- https://issues.asterisk.org/view.php?id=16517
- https://issues.asterisk.org/view.php?id=16634
- https://issues.asterisk.org/view.php?id=16724
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.