[asterisk-users] AST-2009-006: IAX2 Call Number Resource Exhaustion

Gordon Henderson gordon+asterisk at drogon.net
Fri Sep 4 01:05:14 CDT 2009


On Thu, 3 Sep 2009, Asterisk Security Team wrote:

>   +------------------------------------------------------------------------+
>   | Discussion | A lot of time was spent trying to come up with a way to   |
>   |            | resolve this issue in a way that was completely backwards |
>   |            | compatible. However, the final resolution ended up        |
>   |            | requiring a modification to the IAX2 protocol. This       |
>   |            | modification is referred to as call token validation.     |
>   |            | Call token validation is used as a handshake before call  |
>   |            | numbers are assigned to IAX2 connections.                 |

Does this mean that if I upgrade one system, then I have to upgrade all of 
them because IAX will no-longer work between existing systems and upgraded 
ones?

Gordon



More information about the asterisk-users mailing list