From: Kevin Harwell Date: Wed, 31 Jan 2018 19:37:54 +0000 (-0600) Subject: AST-2018-003: Crash with an invalid SDP fmtp attribute X-Git-Tag: 14.7.6~1^2 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=4e9849c4bc706f6c1ca8c7866402e732c322df6f;p=thirdparty%2Fasterisk.git AST-2018-003: Crash with an invalid SDP fmtp attribute pjproject's fmtp retrieval function failed to catch invalid fmtp attributes. Because of this Asterisk would crash if given an SDP with an invalid fmtp attribute. When retrieving the format this patch now makes sure the fmtp attribute is available. If not available it now returns an error status. ASTERISK-27583 #close Change-Id: I5cebe000ce2d846cae3af33b6d72c416e51caf2f --- diff --git a/third-party/pjproject/patches/0071-sdp_fmtp_attr.patch b/third-party/pjproject/patches/0071-sdp_fmtp_attr.patch new file mode 100644 index 0000000000..8228d5dd62 --- /dev/null +++ b/third-party/pjproject/patches/0071-sdp_fmtp_attr.patch @@ -0,0 +1,34 @@ +diff --git a/pjmedia/src/pjmedia/sdp.c b/pjmedia/src/pjmedia/sdp.c +index a3dd80b..6117e07 100644 +--- a/pjmedia/src/pjmedia/sdp.c ++++ b/pjmedia/src/pjmedia/sdp.c +@@ -256,7 +256,8 @@ PJ_DEF(pj_status_t) pjmedia_sdp_attr_get_rtpmap( const pjmedia_sdp_attr *attr, + + PJ_ASSERT_RETURN(pj_strcmp2(&attr->name, "rtpmap")==0, PJ_EINVALIDOP); + +- PJ_ASSERT_RETURN(attr->value.slen != 0, PJMEDIA_SDP_EINATTR); ++ if (attr->value.slen == 0) ++ return PJMEDIA_SDP_EINATTR; + + init_sdp_parser(); + +@@ -341,6 +342,9 @@ PJ_DEF(pj_status_t) pjmedia_sdp_attr_get_fmtp( const pjmedia_sdp_attr *attr, + + PJ_ASSERT_RETURN(pj_strcmp2(&attr->name, "fmtp")==0, PJ_EINVALIDOP); + ++ if (attr->value.slen == 0) ++ return PJMEDIA_SDP_EINATTR; ++ + /* fmtp BNF: + * a=fmtp: + */ +@@ -379,6 +383,9 @@ PJ_DEF(pj_status_t) pjmedia_sdp_attr_get_rtcp(const pjmedia_sdp_attr *attr, + + PJ_ASSERT_RETURN(pj_strcmp2(&attr->name, "rtcp")==0, PJ_EINVALIDOP); + ++ if (attr->value.slen == 0) ++ return PJMEDIA_SDP_EINATTR; ++ + init_sdp_parser(); + + /* fmtp BNF: