mirror of
https://github.com/asterisk/asterisk.git
synced 2025-10-22 20:56:39 +00:00
AST-2012-009: Fix crash in chan_skinny due to Key Pad Button Message handling
AST-2012-008 (r367844) fixed a denial of service attack exploitable in the Skinny channel driver that occurred when certain messages are sent after a previously registered station sends an Off Hook message. Unresolved in that patch is an issue in the Asterisk 10 releases, wherein, if a Station Key Pad Button Message is processed after an Off Hook message, the channel driver will inappropriately dereference a NULL pointer. This patch fixes those places where the message handling or the channel callback functions would attempt to dereference the line's pointer to the device. (issue ASTERISK-19905) Reported by: Christoph Hebeisen Tested by: mjordan, Christoph Hebeisen Patches: AST-2012-009-10.diff uploaded by mjordan (license 6283) ........ Merged revisions 368947 from http://svn.asterisk.org/svn/asterisk/branches/10 git-svn-id: https://origsvn.digium.com/svn/asterisk/trunk@368948 65c4cc65-6c06-0410-ace0-fbb531ad65f3
This commit is contained in:
@@ -5011,6 +5011,11 @@ static void setsubstate(struct skinny_subchannel *sub, int state)
|
||||
pthread_t t;
|
||||
int actualstate = state;
|
||||
|
||||
if (!l->device) {
|
||||
ast_log(LOG_WARNING, "Device for line %s is not registered.\n", l->name);
|
||||
return;
|
||||
}
|
||||
|
||||
if (sub->substate == SUBSTATE_ONHOOK) {
|
||||
return;
|
||||
}
|
||||
@@ -5403,15 +5408,20 @@ static void dumpsub(struct skinny_subchannel *sub, int forcehangup)
|
||||
struct skinny_subchannel *activate_sub = NULL;
|
||||
struct skinny_subchannel *tsub;
|
||||
|
||||
if (!l->device) {
|
||||
ast_log(LOG_WARNING, "Device for line %s is not registered.\n", l->name);
|
||||
return;
|
||||
}
|
||||
|
||||
if (skinnydebug) {
|
||||
ast_verb(3, "Sub %d - Dumping\n", sub->callid);
|
||||
}
|
||||
|
||||
|
||||
if (!forcehangup && sub->substate == SUBSTATE_HOLD) {
|
||||
l->activesub = NULL;
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
if (sub == l->activesub) {
|
||||
d->hookstate = SKINNY_ONHOOK;
|
||||
transmit_speaker_mode(d, SKINNY_SPEAKEROFF);
|
||||
|
Reference in New Issue
Block a user