fixes crash in "scheduled_destroy" in chan_iax

A signed short was used to represent a callnumber.  This is makes
it possible to attempt to access the iaxs array with a negative
index.

(closes issue #16565)
Reported by: jensvb



git-svn-id: https://origsvn.digium.com/svn/asterisk/branches/1.4@238411 65c4cc65-6c06-0410-ace0-fbb531ad65f3
This commit is contained in:
David Vossel
2010-01-07 20:14:25 +00:00
parent a6bc57fe40
commit fed58bd1d6
+1 -1
View File
@@ -1507,7 +1507,7 @@ retry:
static int scheduled_destroy(const void *vid)
{
short callno = PTR_TO_CALLNO(vid);
unsigned short callno = PTR_TO_CALLNO(vid);
ast_mutex_lock(&iaxsl[callno]);
if (iaxs[callno]) {
if (option_debug) {