Details
Description
Easily reproducable. Send any message to asterisk with "From: tel:+1000" in the headers.
The crash is in pjsip_message_ip_updater.c:sanitize_tdata. When we respond with even a 401, that function is called but it assumes that the From, To, and Contact uris are sip uris and casts the header's URI to pjsip_sip_uri *uri. It then tries to call pjsip_param_find on uri->other_param. Since the uri is actually a tel uri and other_param isn't at the same offset in pjsip_sip_uri as it is in pjsip_tel_uri, we get a crash.
Issue Links
- is caused by
-
SWP-9842 Loading...
Thanks for creating a report! The issue has entered the triage process. That means the issue will wait in this status until a Bug Marshal has an opportunity to review the issue. Once the issue has been reviewed you will receive comments regarding the next steps towards resolution.
A good first step is for you to review the Asterisk Issue Guidelines if you haven't already. The guidelines detail what is expected from an Asterisk issue report.
Then, if you are submitting a patch, please review the Patch Contribution Process.