[Freeswitch-users] patch for sofia_sip_i_invite to support replaces with action

Michael Jerris mike at jerris.com
Wed Apr 22 16:20:05 MSD 2015


Couldn't this be a huge security vulnerability used to inject arbitrary
commands into a session in FreeSWITCH?

On Wednesday, April 22, 2015, Luis Azedo <luis.azedo at factorlusitano.com>
wrote:

> Hi,
>
> i need a inline custom action passed with an INVITE msg with a replaces
> header
> or a better to use this scenario.
>
> right now, for calls with replaces header there is support for sla,
> intercept and attendant transfer.
>
> my problem is that intercept requires the bridge_uuid which is not set
> on one leg calls (on hold playing music) so the intercept condition
> won't be hit.
>
> the attendant transfer takes app/data applies and then hangs up the call.
>
> i need a simple answer,intercept:(sip->sip_replaces->rp_call_id)
> instead of bridge_uuid.
>
> i tried to set signal_bond and originate_signal_bound on the channel
> to see if i could bypass this, but with no luck.
>
> i created a small patch that i am attaching here with the hope that
> FreeSWITCH will look and possibly merge it.
>
> Best
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.freeswitch.org/pipermail/freeswitch-users/attachments/20150422/48885f3f/attachment.html 


Join us at ClueCon 2016 Aug 8-12, 2016
More information about the FreeSWITCH-users mailing list