[asterisk-bugs] [Asterisk 0015841]: double free or corruption (!prev) in moh_files_generator

Asterisk Bug Tracker noreply at bugs.digium.com
Wed Oct 7 05:09:15 CDT 2009


A NOTE has been added to this issue. 
====================================================================== 
https://issues.asterisk.org/view.php?id=15841 
====================================================================== 
Reported By:                amorsen
Assigned To:                
====================================================================== 
Project:                    Asterisk
Issue ID:                   15841
Category:                   Resources/res_musiconhold
Reproducibility:            random
Severity:                   crash
Priority:                   normal
Status:                     feedback
Asterisk Version:           Older 1.6.0 
JIRA:                        
Regression:                 No 
Reviewboard Link:            
SVN Branch (only for SVN checkouts, not tarball releases): N/A 
SVN Revision (number only!):  
Request Review:              
====================================================================== 
Date Submitted:             2009-09-07 04:10 CDT
Last Modified:              2009-10-07 05:09 CDT
====================================================================== 
Summary:                    double free or corruption (!prev) in
moh_files_generator
Description: 
Just a copy of 0015195. We don't even load asterisk-addons, so the proposed
patch is a noop. Sorry I didn't respond earlier, but I have been on
vacation.

It is rather silly that I cannot simply reopen the bug. "Older 1.6.0" is
1.6.0.13, all the information in bug 15195 still applies. We won't be able
to run Asterisk under Valgrind in production.
======================================================================
Relationships       ID      Summary
----------------------------------------------------------------------
parent of           0015195 double free or corruption (!prev) in mo...
related to          0015845 Crash during attended transfer occurs
====================================================================== 

---------------------------------------------------------------------- 
 (0111958) amorsen (reporter) - 2009-10-07 05:09
 https://issues.asterisk.org/view.php?id=15841#c111958 
---------------------------------------------------------------------- 
It seems like this patch also prevents the following crash:

==27820== Process terminating with default action of signal 11 (SIGSEGV):
dumping core
==27820==  General Protection Fault
==27820==    at 0x4C26094: strcmp (mc_replace_strmem.c:337)
==27820==    by 0x9251CAB: local_devicestate (chan_local.c:150)
==27820==    by 0x453073: _ast_device_state (devicestate.c:331)
==27820==    by 0x453247: do_state_change (devicestate.c:439)
==27820==    by 0x453321: do_devstate_changes (devicestate.c:517)
==27820==    by 0x4CCFE7: dummy_start (utils.c:861)
==27820==    by 0x5B7A869: start_thread (in /lib64/libpthread-2.10.1.so)
==27820==    by 0x54DC39C: clone (in /lib64/libc-2.10.1.so)

(This was logged by valgrind on a server without the patch.) 

Issue History 
Date Modified    Username       Field                    Change               
====================================================================== 
2009-10-07 05:09 amorsen        Note Added: 0111958                          
======================================================================




More information about the asterisk-bugs mailing list