Skip to content
Snippets Groups Projects
Commit a877e0d9 authored by Richard Mudgett's avatar Richard Mudgett
Browse files

AST-2016-002 chan_sip.c: Fix retransmission timeout integer overflow.

Setting the sip.conf timert1 value to a value higher than 1245 can cause
an integer overflow and result in large retransmit timeout times.  These
large timeout times hold system file descriptors hostage and can cause the
system to run out of file descriptors.

NOTE: The default sip.conf timert1 value is 500 which does not expose the
vulnerability.

* The overflow is now detected and the previous timeout time is
calculated.

ASTERISK-25397 #close
Reported by: Alexander Traud

Change-Id: Ia7231f2f415af1cbf90b923e001b9219cff46290
parent ae1f728f
No related branches found
No related tags found
No related merge requests found
......@@ -3970,6 +3970,13 @@ static int retrans_pkt(const void *data)
}
 
/* For non-invites, a maximum of 4 secs */
if (INT_MAX / pkt->timer_a < pkt->timer_t1) {
/*
* Uh Oh, we will have an integer overflow.
* Recalculate previous timeout time instead.
*/
pkt->timer_a = pkt->timer_a / 2;
}
siptimer_a = pkt->timer_t1 * pkt->timer_a; /* Double each time */
if (pkt->method != SIP_INVITE && siptimer_a > 4000) {
siptimer_a = 4000;
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment