CVE-2010-0441
Publication date 4 February 2010
Last updated 24 July 2024
Ubuntu priority
Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.
Status
Package | Ubuntu Release | Status |
---|---|---|
asterisk | 11.04 natty |
Not affected
|
10.10 maverick |
Not affected
|
|
10.04 LTS lucid |
Not affected
|
|
9.10 karmic | Ignored end of life | |
9.04 jaunty | Ignored end of life | |
8.10 intrepid | Ignored end of life, was needs-triage | |
8.04 LTS hardy |
Not affected
|
|
6.06 LTS dapper | Ignored end of life |
Patch details
Package | Patch details |
---|---|
asterisk |