[asterisk-security] AST-2008-006 - 3-way handshake in IAX2 incomplete

Johansson Olle E oej at edvina.net
Wed Apr 23 11:09:52 CDT 2008


23 apr 2008 kl. 17.59 skrev Russell Bryant:

> Johansson Olle E wrote:
>> Does this change affect *all* IAX2 clients and libraries, not only
>> Asterisk?
>
> Not necessarily.  This was just a flaw in the Asterisk  
> implementation of IAX2
> that this call number was never verified.
>
>> Is it a change of the protocol which means that we have to update the
>> IAX2 draft?
>
> No.  The fix for this issue did not involve a protocol change of any  
> kind.

Thank you for the clarification!

Greetings from Florida.

/O



More information about the asterisk-security mailing list