[FFmpeg-devel] [PATCH] avformat/oggparseflac: check init_get_bits' result
James Almer
jamrial at gmail.com
Wed May 31 00:28:32 EEST 2023
On 5/30/2023 6:21 PM, Paul Arzelier wrote:
> From: Polochon-street <polochonstreet at gmx.fr>
>
> Check init_get_bits' result for NULL, to avoid dereferencing a NULL
> pointer later (CWE-476).
> Without this, a segfault happens when trying to decode a handcrafted
> ogg-flac file with an absurdly long (e.g. 268435455 bytes) ogg header.
>
> Thanks to jamrial for basically writing this patch after I reported the bug!
>
> Signed-off-by: Paul Arzelier <paul.arzelier at free.fr>
Applied.
More information about the ffmpeg-devel
mailing list