Skip to content
  • Pablo Neira Ayuso's avatar
    netfilter: nf_ct_h323: fix bug in rtcp natting · d109e9af
    Pablo Neira Ayuso authored
    
    
    The nat_rtp_rtcp hook takes two separate parameters port and rtp_port.
    
    port is expected to be the real h245 address (found inside the packet).
    rtp_port is the even number closest to port (RTP ports are even and
    RTCP ports are odd).
    
    However currently, both port and rtp_port are having same value (both are
    rounded to nearest even numbers).
    
    This works well in case of openlogicalchannel with media (RTP/even) port.
    
    But in case of openlogicalchannel for media control (RTCP/odd) port,
    h245 address in the packet is wrongly modified to have an even port.
    
    I am attaching a pcap demonstrating the problem, for any further analysis.
    
    This behavior was introduced around v2.6.19 while rewriting the helper.
    
    Signed-off-by: default avatarJagdish Motwani <jagdish.motwani@elitecore.com>
    Signed-off-by: default avatarSanket Shah <sanket.shah@elitecore.com>
    Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
    d109e9af