CVE-2010-0441: Input Validation
Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0441?
CVE-2010-0441 is categorized as a denial of service vulnerability that can cause the Asterisk daemon to crash.
How do I fix CVE-2010-0441?
To fix CVE-2010-0441, upgrade to Asterisk versions 1.6.0.22, 1.6.1.14, 1.6.2.2, or Business Edition C.3.3.2 or later.
What software is affected by CVE-2010-0441?
CVE-2010-0441 affects Asterisk versions 1.6.0.x, 1.6.1.x, 1.6.2.x, and Business Edition C.3 prior to the specified updates.
Can CVE-2010-0441 be exploited remotely?
Yes, CVE-2010-0441 can be exploited by remote attackers to cause a denial of service.
What are the symptoms of CVE-2010-0441 being exploited?
The symptoms of CVE-2010-0441 exploitation include Asterisk daemon crashes and potential service outages.