[asterisk-bugs] [JIRA] (ASTERISK-29024) Route Header in Cancel request incorrectly set

Kevin Harwell (JIRA) noreply at issues.asterisk.org
Mon Aug 10 18:01:43 CDT 2020


    [ https://issues.asterisk.org/jira/browse/ASTERISK-29024?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=251613#comment-251613 ] 

Kevin Harwell edited comment on ASTERISK-29024 at 8/10/20 6:01 PM:
-------------------------------------------------------------------

Does this happen every time?

Please enable debug and SIP tracing in the Asterisk log [1], and attach to this issue the output of an incident.

Also please attach relevant dialplan and _pjsip.conf_ (endpoint definition, etc...) configuration.

[1] https://wiki.asterisk.org/wiki/display/AST/Collecting+Debug+Information

Thanks!


was (Author: kharwell):
Does this happen everytime?

Please enable debug and SIP tracing in the Asterisk log [1], and attach to this issue the output of an incident.

Also please attach relevant dialplan and _pjsip.conf_ (endpoint definition, etc...) configuration.

[1] https://wiki.asterisk.org/wiki/display/AST/Collecting+Debug+Information

Thanks!

> Route Header in Cancel request incorrectly set
> ----------------------------------------------
>
>                 Key: ASTERISK-29024
>                 URL: https://issues.asterisk.org/jira/browse/ASTERISK-29024
>             Project: Asterisk
>          Issue Type: Bug
>      Security Level: None
>          Components: pjproject/pjsip
>    Affects Versions: 17.6.0
>            Reporter: Flole Systems
>
> When I initiate a call using PJSIP and Cancel the call while it's still ringing the Route-Header seems to be sent incorrectly. It looks like it's a pointer to a memory region that got overwritten. I saw internal IP Addresses in there aswell as some other stuff like "Route: <sip:}". The "Route: <sip:" is always set properly, just the part after the sip is never set correctly and also the closing ">" is always missing.
> As the memory region that it reads from can't be controlled it might happen that confidential data like a password is exposed over this.



--
This message was sent by Atlassian JIRA
(v6.2#6252)



More information about the asterisk-bugs mailing list