Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-0441

Опубликовано: 04 фев. 2010
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:asterisk:asterisk:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.5:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.6:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.7:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.8:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.9:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.10:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.12:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.13:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.14:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.15:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.16-rc1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.16-rc2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.17:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.18:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.18-rc1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.18-rc2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.18-rc3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.19:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.20:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.20-rc1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.21:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.0.21-rc1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.5:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.6:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.7-rc1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.7-rc2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.8:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.9:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.10:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.10-rc1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.10-rc2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.10-rc3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.11:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.12:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.12-rc1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.13:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.1.13-rc1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.2.1-rc1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.10-rc1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6.10-rc2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:c.3.1.0:*:business:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:c.3.1.1:*:business:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:c.3.2.2:*:business:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:c.3.3.3:*:business:*:*:*:*:*

EPSS

Процентиль: 87%
0.03526
Низкий

5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 16 лет назад

Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.

redhat
почти 16 лет назад

Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.

debian
почти 16 лет назад

Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, ...

github
больше 3 лет назад

Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.

EPSS

Процентиль: 87%
0.03526
Низкий

5 Medium

CVSS2

Дефекты

CWE-20