Fix a possible crash in pbx_spool.

We were trying to reference members of a struct that had previously been freed.
This patch makes sure that we free the struct after it has been removed from
the spooler queue.

(closes issue #15072)
Reported by: garlew
Patches:
      spool.diff uploaded by garlew (license 376)


git-svn-id: https://origsvn.digium.com/svn/asterisk/branches/1.4@198957 65c4cc65-6c06-0410-ace0-fbb531ad65f3
This commit is contained in:
Sean Bright
2009-06-03 20:39:10 +00:00
parent ddb4e3f2e7
commit f3b85fface

View File

@@ -419,20 +419,20 @@ static int scan_service(char *fn, time_t now, time_t atime)
return now;
} else {
ast_log(LOG_EVENT, "Queued call to %s/%s expired without completion after %d attempt%s\n", o->tech, o->dest, o->retries - 1, ((o->retries - 1) != 1) ? "s" : "");
free_outgoing(o);
remove_from_queue(o, "Expired");
free_outgoing(o);
return 0;
}
} else {
free_outgoing(o);
ast_log(LOG_WARNING, "Invalid file contents in %s, deleting\n", fn);
fclose(f);
remove_from_queue(o, "Failed");
free_outgoing(o);
}
} else {
free_outgoing(o);
ast_log(LOG_WARNING, "Unable to open %s: %s, deleting\n", fn, strerror(errno));
remove_from_queue(o, "Failed");
free_outgoing(o);
}
} else
ast_log(LOG_WARNING, "Out of memory :(\n");