security bug in cvs2.07

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Just discovered that when a gateway registers with the GNUgk v2.07cvs with
an alias(or dialeddigits) and then gets an additional alias(or dialeddigits)
and re-registers, the original registration endpoint id is issued and the
endpoint table seems to have allow calls to the new alias but the cdrs do
not appear for calls made or attempted to the new alias (or dialeddigits).

This way a participating gateway can fool the GK into allowing calls to the
additional alias without getting it CDRed.

Ap.Muthu




-------------------------------------------------------
This SF.net email is sponsored by: Perforce Software.
Perforce is the Fast Software Configuration Management System offering
advanced branching capabilities and atomic changes on 50+ platforms.
Free Eval! http://www.perforce.com/perforce/loadprog.html
_______________________________________________
List: Openh323gk-users@lists.sourceforge.net
Archive: http://sourceforge.net/mailarchive/forum.php?forum_id=8549
Homepage: http://www.gnugk.org/

[Index of Archives]     [SIP]     [Open H.323]     [Gnu Gatekeeper]     [Asterisk PBX]     [ISDN Cause Codes]     [Yosemite News]

  Powered by Linux