[FFmpeg-devel] [PATCH 4/8] avutil/avstring: Limit string length in av_escape to range of int

Andreas Rheinhardt andreas.rheinhardt at gmail.com
Wed Mar 10 03:05:57 EET 2021


Otherwise the caller can't distinguish the return value from an error.

Signed-off-by: Andreas Rheinhardt <andreas.rheinhardt at gmail.com>
---
 libavutil/avstring.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavutil/avstring.c b/libavutil/avstring.c
index e33d4aac51..832bec750f 100644
--- a/libavutil/avstring.c
+++ b/libavutil/avstring.c
@@ -337,7 +337,7 @@ int av_escape(char **dst, const char *src, const char *special_chars,
 {
     AVBPrint dstbuf;
 
-    av_bprint_init(&dstbuf, 1, AV_BPRINT_SIZE_UNLIMITED);
+    av_bprint_init(&dstbuf, 1, INT_MAX); /* (int)dstbuf.len must be >= 0 */
     av_bprint_escape(&dstbuf, src, special_chars, mode, flags);
 
     if (!av_bprint_is_complete(&dstbuf)) {
-- 
2.27.0



More information about the ffmpeg-devel mailing list