[asterisk-bugs] [JIRA] (ASTERISK-26107) chan_sip: ASAN: heap-buffer-overflow on sip reload

Joshua Colp (JIRA) noreply at issues.asterisk.org
Fri Jun 10 08:26:56 CDT 2016


     [ https://issues.asterisk.org/jira/browse/ASTERISK-26107?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Joshua Colp updated ASTERISK-26107:
-----------------------------------

    Summary: chan_sip: ASAN: heap-buffer-overflow on sip reload  (was: ASAN: heap-buffer-overflow on sip reload)

> chan_sip: ASAN: heap-buffer-overflow on sip reload
> --------------------------------------------------
>
>                 Key: ASTERISK-26107
>                 URL: https://issues.asterisk.org/jira/browse/ASTERISK-26107
>             Project: Asterisk
>          Issue Type: Bug
>      Security Level: None
>          Components: Channels/chan_sip/General
>    Affects Versions: 13.9.1
>            Reporter: Badalian Vyacheslav
>
> {code}
> =================================================================
> ==30286==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x619001136655 at pc 0x7fa3fbec7bd7 bp 0x7fa3f6336160 sp 0x7fa3f6336150
> READ of size 1 at 0x619001136655 thread T432
>     #0 0x7fa3fbec7bd6 in peer_markall_func /root/asterisk-13.9.1/channels/chan_sip.c:31749
>     #1 0x494dc4 in internal_ao2_traverse /root/asterisk-13.9.1/main/astobj2_container.c:351
>     #2 0x4951c8 in __ao2_callback /root/asterisk-13.9.1/main/astobj2_container.c:452
>     #3 0x7fa3fbec9232 in reload_config /root/asterisk-13.9.1/channels/chan_sip.c:31924
>     #4 0x7fa3fbed8080 in sip_do_reload /root/asterisk-13.9.1/channels/chan_sip.c:33692
>     #5 0x7fa3fbe9f749 in do_monitor /root/asterisk-13.9.1/channels/chan_sip.c:29410
>     #6 0x7e58b5 in dummy_start /root/asterisk-13.9.1/main/utils.c:1235
>     #7 0x7fa430179dc4 in start_thread (/lib64/libpthread.so.0+0x7dc4)
>     #8 0x7fa42f45928c in clone (/lib64/libc.so.6+0xf628c)
> {code}



--
This message was sent by Atlassian JIRA
(v6.2#6252)



More information about the asterisk-bugs mailing list