Asterisk
  1. Asterisk
  2. ASTERISK-25893

Function vmauthenticate accesses uninitialized memory

    Details

    • Regression:
      No

      Description

      The problem is in function vmauthenticate, on lines

      	if (!vm_authenticate(chan, mailbox, sizeof(mailbox), &vmus, context, NULL, skipuser, 3, silent)) {
      		pbx_builtin_setvar_helper(chan, "AUTH_MAILBOX", mailbox);
      		pbx_builtin_setvar_helper(chan, "AUTH_CONTEXT", vmus.context);
      

      If skipuser>0, then vm_authenticate does not fill the vmus variable, because of the condition:

      	if (vmu && !skipuser) {
      		memcpy(res_vmu, vmu, sizeof(struct ast_vm_user));
      	}
      

      The result is that AUTH_CONTEXT is set with an uninitialized memory, following errors are logged:

      [06/Apr/2016 04:51:12] asterisk[32621] [C-00000000]json.c:704 in ast_json_vpack: Error building JSON from '{s: s, s: s}': Invalid UTF-8 string.
      [06/Apr/2016 04:51:12] asterisk[32621] [C-00000000]stasis_channels.c:774 in ast_channel_publish_varset: Error creating message name=AUTH_CONTEXT value=ެ��
      

        Activity

        Hide
        Asterisk Team added a comment -

        Thanks for creating a report! The issue has entered the triage process. That means the issue will wait in this status until a Bug Marshal has an opportunity to review the issue. Once the issue has been reviewed you will receive comments regarding the next steps towards resolution.

        A good first step is for you to review the Asterisk Issue Guidelines if you haven't already. The guidelines detail what is expected from an Asterisk issue report.

        Then, if you are submitting a patch, please review the Patch Contribution Process.

        Show
        Asterisk Team added a comment - Thanks for creating a report! The issue has entered the triage process. That means the issue will wait in this status until a Bug Marshal has an opportunity to review the issue. Once the issue has been reviewed you will receive comments regarding the next steps towards resolution. A good first step is for you to review the Asterisk Issue Guidelines if you haven't already. The guidelines detail what is expected from an Asterisk issue report. Then, if you are submitting a patch, please review the Patch Contribution Process .
        Hide
        Rusty Newton added a comment -

        Thanks for the report. Do you want to provide a patch on Gerrit[1] to help get a fix in faster?

        [1]: https://wiki.asterisk.org/wiki/display/AST/Gerrit+Usage

        Show
        Rusty Newton added a comment - Thanks for the report. Do you want to provide a patch on Gerrit [1] to help get a fix in faster? [1] : https://wiki.asterisk.org/wiki/display/AST/Gerrit+Usage
        Hide
        Asterisk Team added a comment -

        Suspended due to lack of activity. This issue will be automatically re-opened if the reporter posts a comment. If you are not the reporter and would like this re-opened please create a new issue instead. If the new issue is related to this one a link will be created during the triage process. Further information on issue tracker usage can be found in the Asterisk Issue Guidlines [1].

        [1] https://wiki.asterisk.org/wiki/display/AST/Asterisk+Issue+Guidelines

        Show
        Asterisk Team added a comment - Suspended due to lack of activity. This issue will be automatically re-opened if the reporter posts a comment. If you are not the reporter and would like this re-opened please create a new issue instead. If the new issue is related to this one a link will be created during the triage process. Further information on issue tracker usage can be found in the Asterisk Issue Guidlines [1] . [1] https://wiki.asterisk.org/wiki/display/AST/Asterisk+Issue+Guidelines
        Hide
        Friendly Automation added a comment -

        Change 5019 merged by zuul:
        app_voicemail: vm_authenticate accesses uninitialized memory

        https://gerrit.asterisk.org/5019

        Show
        Friendly Automation added a comment - Change 5019 merged by zuul: app_voicemail: vm_authenticate accesses uninitialized memory https://gerrit.asterisk.org/5019
        Hide
        Friendly Automation added a comment -

        Change 5020 merged by zuul:
        app_voicemail: vm_authenticate accesses uninitialized memory

        https://gerrit.asterisk.org/5020

        Show
        Friendly Automation added a comment - Change 5020 merged by zuul: app_voicemail: vm_authenticate accesses uninitialized memory https://gerrit.asterisk.org/5020
        Hide
        Friendly Automation added a comment -

        Change 5021 merged by zuul:
        app_voicemail: vm_authenticate accesses uninitialized memory

        https://gerrit.asterisk.org/5021

        Show
        Friendly Automation added a comment - Change 5021 merged by zuul: app_voicemail: vm_authenticate accesses uninitialized memory https://gerrit.asterisk.org/5021

          People

          • Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development