[Asterisk-code-review] chan sip: Fix buffer overrun in sip sipredirect. (asterisk[11])

Corey Farrell asteriskteam at digium.com
Mon Jan 25 11:12:47 CST 2016


Corey Farrell has uploaded a new change for review.

  https://gerrit.asterisk.org/2080

Change subject: chan_sip: Fix buffer overrun in sip_sipredirect.
......................................................................

chan_sip: Fix buffer overrun in sip_sipredirect.

sip_sipredirect uses sscanf to copy up to 256 characters to a stacked buffer
of 256 characters.  This patch reduces the copy to 255 characters to leave
room for the string null terminator.

ASTERISK-25722 #close

Change-Id: Id6c3a629a609e94153287512c59aa1923e8a03ab
---
M channels/chan_sip.c
1 file changed, 2 insertions(+), 2 deletions(-)


  git pull ssh://gerrit.asterisk.org:29418/asterisk refs/changes/80/2080/1

diff --git a/channels/chan_sip.c b/channels/chan_sip.c
index bd2f398..5436ab3 100644
--- a/channels/chan_sip.c
+++ b/channels/chan_sip.c
@@ -33395,8 +33395,8 @@
 
 			memset(ldomain, 0, sizeof(ldomain));
 			local_to_header++;
-			/* This is okey because lhost and lport are as big as tmp */
-			sscanf(local_to_header, "%256[^<>; ]", ldomain);
+			/* Will copy no more than 255 chars plus null terminator. */
+			sscanf(local_to_header, "%255[^<>; ]", ldomain);
 			if (ast_strlen_zero(ldomain)) {
 				ast_log(LOG_ERROR, "Can't find the host address\n");
 				return 0;

-- 
To view, visit https://gerrit.asterisk.org/2080
To unsubscribe, visit https://gerrit.asterisk.org/settings

Gerrit-MessageType: newchange
Gerrit-Change-Id: Id6c3a629a609e94153287512c59aa1923e8a03ab
Gerrit-PatchSet: 1
Gerrit-Project: asterisk
Gerrit-Branch: 11
Gerrit-Owner: Corey Farrell <git at cfware.com>



More information about the asterisk-code-review mailing list