diff options
author | jpeeler <jpeeler@f38db490-d61c-443f-a65b-d21fe96a405b> | 2010-01-26 18:07:57 +0000 |
---|---|---|
committer | jpeeler <jpeeler@f38db490-d61c-443f-a65b-d21fe96a405b> | 2010-01-26 18:07:57 +0000 |
commit | 663d04ef2eb46fae172e9c5b1353a07474a97a67 (patch) | |
tree | 1fbeea494c723481b854f7fc5b3a855fe4af303e /main/frame.c | |
parent | 88b11a8da58bbde8263bae6a68539898191e8c30 (diff) |
Fix crash resulting from frames with invalid data pointers.
In ast_frdup the frame data union does not get set to point to malloced memory
if the datalen is zero, so make sure to handle the same case in ast_frisolate
appropriately.
(closes issue #16058)
Reported by: atis
Patches:
bug16058-fix.patch uploaded by jpeeler (license 325)
Tested by: atis
git-svn-id: http://svn.digium.com/svn/asterisk/trunk@243244 f38db490-d61c-443f-a65b-d21fe96a405b
Diffstat (limited to 'main/frame.c')
-rw-r--r-- | main/frame.c | 5 |
1 files changed, 5 insertions, 0 deletions
diff --git a/main/frame.c b/main/frame.c index 1f1476c7c..c90469bba 100644 --- a/main/frame.c +++ b/main/frame.c @@ -435,6 +435,11 @@ struct ast_frame *ast_frisolate(struct ast_frame *fr) } if (!(fr->mallocd & AST_MALLOCD_DATA)) { + if (!fr->datalen) { + out->data.uint32 = fr->data.uint32; + out->mallocd = AST_MALLOCD_HDR | AST_MALLOCD_SRC; + return out; + } if (!(newdata = ast_malloc(fr->datalen + AST_FRIENDLY_OFFSET))) { if (out->src != fr->src) { ast_free((void *) out->src); |