Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.800463
Category:Denial of Service
Title:Asterisk T.38 Negotiation Remote DoS Vulnerability (AST-2010-001)
Summary:Asterisk is prone to a denial of service (DoS) vulnerability.
Description:Summary:
Asterisk is prone to a denial of service (DoS) vulnerability.

Vulnerability Insight:
The flaw is caused by an error when handling 'T.38 negotiations'
over SIP with a negative or overly large value in the 'FaxMaxDatagram' field, or without any
'FaxMaxDatagram' field, which could allows attackers to crash a server.

Vulnerability Impact:
Successful exploitation could result in denial of service
condition.

Affected Software/OS:
Asterisk version 1.6.0.x prior to 1.6.0.22, 1.6.1.x prior to
1.6.1.14 and 1.6.2.x prior to 1.6.2.2.

Solution:
Update to version 1.6.0.22, 1.6.1.14, 1.6.2.2 or apply the
patch from the linked references.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-0441
BugTraq ID: 38047
http://www.securityfocus.com/bid/38047
Bugtraq: 20100202 AST-2010-001: T.38 Remote Crash Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/509327/100/0/threaded
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037679.html
http://securitytracker.com/id?1023532
http://secunia.com/advisories/38395
http://secunia.com/advisories/39096
http://www.vupen.com/english/advisories/2010/0289
CopyrightCopyright (C) 2010 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.