Vulnerabilities > Asterisk > Asterisk > 1.6.0.8

DATE CVE VULNERABILITY TITLE RISK
2010-02-04 CVE-2010-0441 Improper Input Validation vulnerability in Asterisk
Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.
network
low complexity
asterisk CWE-20
5.0