Vulnerable Systems:
* Asterisk Open Source 1.6.x - All versions
* Asterisk Business Edition C.3 - All versions
Immune Systems:
* Asterisk Open Source - 1.6.0.22
* Asterisk Open Source - 1.6.1.14
* Asterisk Open Source - 1.6.2.2
* Asterisk Business Edition - C.3.3.2
An attacker attempting to negotiate T.38 over SIP can remotely crash Asterisk by modifying the FaxMaxDatagram field of the SDP to contain either a negative or exceptionally large value. The same crash occurs when the FaxMaxDatagram field is omitted from the SDP as well.