From: Kinsey Moore Date: Wed, 23 Oct 2013 15:23:30 +0000 (+0000) Subject: chan_mgcp: Properly handle malformed media lines X-Git-Tag: 12.0.0-beta2~103 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=b0b7db475c3ac37c2844b7210c6eaaf64f832d16;p=thirdparty%2Fasterisk.git chan_mgcp: Properly handle malformed media lines This corrects a situation in which a media line was not parsed properly and resulted in a crash. (closes issue ASTERISK-21190) Reported by: adomjan Patches: chan_mgcp.c-sscnaf_fix uploaded by adomjan (License 5448) ........ Merged revisions 401537 from http://svn.asterisk.org/svn/asterisk/branches/1.8 ........ Merged revisions 401538 from http://svn.asterisk.org/svn/asterisk/branches/11 git-svn-id: https://origsvn.digium.com/svn/asterisk/branches/12@401539 65c4cc65-6c06-0410-ace0-fbb531ad65f3 --- diff --git a/channels/chan_mgcp.c b/channels/chan_mgcp.c index a659a2aab4..84fb3b2256 100644 --- a/channels/chan_mgcp.c +++ b/channels/chan_mgcp.c @@ -1971,7 +1971,7 @@ static int process_sdp(struct mgcp_subchannel *sub, struct mgcp_request *req) char *c; char *a; char host[258]; - int len; + int len = 0; int portno; struct ast_format_cap *peercap; int peerNonCodecCapability; @@ -2001,8 +2001,8 @@ static int process_sdp(struct mgcp_subchannel *sub, struct mgcp_request *req) ast_log(LOG_WARNING, "Unable to lookup host in c= line, '%s'\n", c); return -1; } - if (sscanf(m, "audio %30d RTP/AVP %n", &portno, &len) != 1) { - ast_log(LOG_WARNING, "Unable to determine port number for RTP in '%s'\n", m); + if (sscanf(m, "audio %30d RTP/AVP %n", &portno, &len) != 1 || !len) { + ast_log(LOG_WARNING, "Malformed media stream descriptor: %s\n", m); return -1; } sin.sin_family = AF_INET;