[FFmpeg-devel] [PATCH] avformat/oggparseflac: check init_get_bits' result

James Almer jamrial at gmail.com
Wed May 31 00:28:32 EEST 2023


On 5/30/2023 6:21 PM, Paul Arzelier wrote:
> From: Polochon-street <polochonstreet at gmx.fr>
> 
> Check init_get_bits' result for NULL, to avoid dereferencing a NULL
> pointer later (CWE-476).
> Without this, a segfault happens when trying to decode a handcrafted
> ogg-flac file with an absurdly long (e.g. 268435455 bytes) ogg header.
> 
> Thanks to jamrial for basically writing this patch after I reported the bug!
> 
> Signed-off-by: Paul Arzelier <paul.arzelier at free.fr>

Applied.


More information about the ffmpeg-devel mailing list