vlc | branch: master | Hugo Beauzée-Luyssen <[email protected]> | Fri May 3 22:42:34 2019 +0200| [af75fb6f24d74e51dbddeca5c6692404e7b25307] | committer: Hugo Beauzée-Luyssen
mkv: Fix potential buffer overflow https://hackerone.com/reports/503218 > http://git.videolan.org/gitweb.cgi/vlc.git/?a=commit;h=af75fb6f24d74e51dbddeca5c6692404e7b25307 --- modules/demux/mkv/matroska_segment_parse.cpp | 2 ++ 1 file changed, 2 insertions(+) diff --git a/modules/demux/mkv/matroska_segment_parse.cpp b/modules/demux/mkv/matroska_segment_parse.cpp index ae888251a8..5a9bc732f5 100644 --- a/modules/demux/mkv/matroska_segment_parse.cpp +++ b/modules/demux/mkv/matroska_segment_parse.cpp @@ -1838,6 +1838,8 @@ bool matroska_segment_c::TrackInit( mkv_track_t * p_tk ) p_tk->fmt.audio.i_bitspersample = GetWLE( &p_wf->wBitsPerSample ); p_tk->fmt.i_extra = GetWLE( &p_wf->cbSize ); + if ( (size_t)p_tk->fmt.i_extra > p_tk->i_extra_data - sizeof( WAVEFORMATEX ) ) + p_tk->fmt.i_extra = 0; if( p_tk->fmt.i_extra != 0 ) { p_tk->fmt.p_extra = xmalloc( p_tk->fmt.i_extra ); _______________________________________________ vlc-commits mailing list [email protected] https://mailman.videolan.org/listinfo/vlc-commits
