[asterisk-bugs] [Asterisk 0015495]: [patch] Asterisk runs over end of buffer reading manager input over HTTP and segfaults

Asterisk Bug Tracker noreply at bugs.digium.com
Wed Sep 16 14:39:33 CDT 2009


A NOTE has been added to this issue. 
====================================================================== 
https://issues.asterisk.org/view.php?id=15495 
====================================================================== 
Reported By:                pdf
Assigned To:                tilghman
====================================================================== 
Project:                    Asterisk
Issue ID:                   15495
Category:                   Core/HTTP
Reproducibility:            sometimes
Severity:                   crash
Priority:                   normal
Status:                     ready for testing
Asterisk Version:           SVN 
Regression:                 No 
SVN Branch (only for SVN checkouts, not tarball releases):  1.4  
SVN Revision (number only!): 206284 
Request Review:              
====================================================================== 
Date Submitted:             2009-07-13 23:11 CDT
Last Modified:              2009-09-16 14:39 CDT
====================================================================== 
Summary:                    [patch] Asterisk runs over end of buffer reading
manager input over HTTP and segfaults
Description: 
We have a number of applications working over manager, and whilst I have
not been able to nail down what precisely is causing this, it has occurred
a number of times.  It looks like xml_translate is looking for a
null-terminated string, but the string is not always null-terminated, so it
runs off the end of the buffer and segfaults.
====================================================================== 

---------------------------------------------------------------------- 
 (0110836) tilghman (administrator) - 2009-09-16 14:39
 https://issues.asterisk.org/view.php?id=15495#c110836 
---------------------------------------------------------------------- 
New patch uploaded that should not generate a warning.  The null character
should not be added at all times when tmpfile is written, because that
would advance the file pointer and cause the string read back out to be
terminated early. 

Issue History 
Date Modified    Username       Field                    Change               
====================================================================== 
2009-09-16 14:39 tilghman       Note Added: 0110836                          
======================================================================




More information about the asterisk-bugs mailing list