[asterisk-bugs] [JIRA] (ASTERISK-25122) Large SIP packet received via pjsip over websocket crashes Asterisk

Asterisk Team (JIRA) noreply at issues.asterisk.org
Wed Jul 27 10:24:02 CDT 2016


     [ https://issues.asterisk.org/jira/browse/ASTERISK-25122?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Asterisk Team updated ASTERISK-25122:
-------------------------------------

    Target Release Version/s: 14.0.0

> Large SIP packet received via pjsip over websocket crashes Asterisk 
> --------------------------------------------------------------------
>
>                 Key: ASTERISK-25122
>                 URL: https://issues.asterisk.org/jira/browse/ASTERISK-25122
>             Project: Asterisk
>          Issue Type: Bug
>      Security Level: None
>          Components: Resources/res_pjsip_transport_websocket
>    Affects Versions: SVN, 13.3.2, 13.4.0
>         Environment: Debian 8, pjsip 2.4
>            Reporter: Ivan Poddubny
>      Target Release: 13.5.0, 14.0.0
>
>
> A regression introduced in 13.2.0 causes a crash when pjsip receives a SIP packet over websocket that is larger than PJSIP_MAX_PKT_LEN. The packet is truncated but the len field in pkg_info is not, thus leading to memory corruption and a segfault.
> The patch is up for review at https://gerrit.asterisk.org/#/c/528/



--
This message was sent by Atlassian JIRA
(v6.2#6252)



More information about the asterisk-bugs mailing list