[OpenSIPS-Users] [OpenSIPS Security Alerts] [FIX] [Severity Medium] Dialog module

Vlad Paiu vladpaiu at opensips.org
Fri Aug 31 15:30:52 CEST 2012


This message was generated by the Security Alerts service ( Free Trial 14th of August - 14th of September )
http://www.opensips.org/Resources/AlertsMain
*
SVN commit*:
http://opensips.svn.sourceforge.net/viewvc/opensips?view=revision&revision=9197

*Severity*: Medium

*Version*  : 1.8, trunk

*Affected modules*  : Dialog

*Effect*  : Distributed Load-Balacing was not working properly

*Affected scenarios*: In a distributed load-balancing setup, the LoadBalancer module
was not properly marking the internally-created dialog profiles as shared,
thus breaking the distributed functionality.

*Description:*  The bug was in the Dialog module. When the LoadBalancer modules used the
Dialog API to create distributed profiles, the Dialog module was mistakenly modifying
the resource name, removing the distributed marker ( /s ). When the LoadBalancer
module would search again for the profile, it couldn't be found anymore.

*Risks*  : When setting up a distributed LoadBalancer setup, each node would not be able
to see the other nodes load, and would end up overloading destination servers.

*Update*  :
- if you have an SVN checkout, 1.8 and trunk were fixed; so
update to a revision later than 9196 (trunk) or 9197 (1.8 branch)
- if you have OpenSIPS from sources, download and apply the patch from
http://opensips.svn.sourceforge.net/viewvc/opensips/branches/1.8/modules/dialog/dlg_profile.c?view=patch&r1=9197&r2=9196&pathrev=9197
or see the attached patch;
- if using tarballs, they were already regenerated (and include the fix)
- If using the official Debian package (apt.opensips.org), they are also
re-generated including the fix.

-- 
Vlad Paiu
OpenSIPS Developer
http://www.opensips-solutions.com

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.opensips.org/pipermail/users/attachments/20120831/64f3e69b/attachment.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: dlg_distributedlb-9197.patch
Type: text/x-diff
Size: 1151 bytes
Desc: not available
URL: <http://lists.opensips.org/pipermail/users/attachments/20120831/64f3e69b/attachment.patch>
-------------- next part --------------
_______________________________________________
Alerts mailing list
Alerts at lists.opensips.org
http://lists.opensips.org/cgi-bin/mailman/listinfo/alerts


More information about the Users mailing list