From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org [79.124.17.100]) by master.gitmailbox.com (Postfix) with ESMTP id E2B8742A9D for ; Thu, 12 May 2022 15:31:08 +0000 (UTC) Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id CBA5B68B461; Thu, 12 May 2022 18:30:55 +0300 (EEST) Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id AC0EB68B3CF for ; Thu, 12 May 2022 18:30:49 +0300 (EEST) Received: by mail-wm1-f45.google.com with SMTP id r188-20020a1c44c5000000b003946c466c17so2737624wma.4 for ; Thu, 12 May 2022 08:30:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=CfV91yG3g9P8ALHqlNrUxdASF6SNyKzb9TLxmqTmJXc=; b=HX/UVTMrIVDiwD8hqNIPIaiuim4b+YC8vlzSR0WmqSpZj+MTMFbTA3DQXgTLBOReQn di3qXDpyp7lZ56G2a5W4MFQ0zn+EaeC/58mfCxCz5/VEb5VlmZpS8PCbQgauk8M12kvL 8jHXZaFd3RQRk8kwOr0CmdJCi3vOiy3GI3cIMJq4Re30qpCaundwgWS8uiJPwZkjBXPk PCiQzh+rLS0yJHImqk7OTWtXzVQXk8VLXgJrfc6SJ3dtEkiJukkQ5EKks/V13R6FYx81 sU5qEPRVLsBGMbkQE2+PvHpNsZa2fKQdLJcZmQSziTWx5JKRTMGBAdKa6zzPS9LpruD5 EHnQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=CfV91yG3g9P8ALHqlNrUxdASF6SNyKzb9TLxmqTmJXc=; b=GjhayAHXeeJ+ifDFq6Wk8mQfZc7t3faDZRx1mrGwSgJx/ZcUHMreXZP0rZqRUj1nNe /NlkmDtqGZA7sfRWf3JZCNQGw535UmdYl3uXm2OngCX8bdWBhC3zNKRfyksdtCZTHPb2 R0mN+3rp5mSEWH9RGl12STWZi5fd1315AyQyzFXAQKwFpyewaUyi7AalUERGozKM7IFn XLKHI8n2u52V4EqAxOX/5ml6q4i7N3ai3O9kU7dZOY7BLaePecBeP4haFvCIiFP3qLd7 0nDb/OiGg7NLQJceFMrOFB4dI8w6CeWSpDvFUw7CV7rJOCqSGN+GDed+OlCGUPTJy+8d 3DIA== X-Gm-Message-State: AOAM533Yevd4X+538RIF6gdKrKNYFqOJTeR7V+wT5xBrzHY3KlwsFnRA qoliNCi/H8Lk3gImUSm5agnRI1TFDcOUbA== X-Google-Smtp-Source: ABdhPJz7jBNQrAF8La5abxlFG70aZfN/Vk2WZJythgdwjkcUiX/etFcEss/xdHTaCqor4d70hkyClQ== X-Received: by 2002:a05:600c:154d:b0:394:8d64:9166 with SMTP id f13-20020a05600c154d00b003948d649166mr390078wmg.102.1652369449156; Thu, 12 May 2022 08:30:49 -0700 (PDT) Received: from localhost.localdomain ([79.173.135.242]) by smtp.gmail.com with ESMTPSA id y25-20020a1c4b19000000b0039489e1bbd6sm2806793wma.47.2022.05.12.08.30.48 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 12 May 2022 08:30:48 -0700 (PDT) From: vectronic To: ffmpeg-devel@ffmpeg.org Date: Thu, 12 May 2022 16:30:19 +0100 Message-Id: <20220512153019.66066-2-hello.vectronic@gmail.com> X-Mailer: git-send-email 2.32.0 (Apple Git-132) In-Reply-To: <20220512153019.66066-1-hello.vectronic@gmail.com> References: <20220512153019.66066-1-hello.vectronic@gmail.com> MIME-Version: 1.0 Subject: [FFmpeg-devel] [PATCH 1/1] fix: use declared size for attribute of type string to ensure full value used and prevent parse failure for string lengths longer than 256 X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Cc: vectronic Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" Archived-At: List-Archive: List-Post: Signed-off-by: vectronic --- libavcodec/exr.c | 32 +++++++++++++++++++++++--------- 1 file changed, 23 insertions(+), 9 deletions(-) diff --git a/libavcodec/exr.c b/libavcodec/exr.c index 8cd867a32f..bc2afcee53 100644 --- a/libavcodec/exr.c +++ b/libavcodec/exr.c @@ -1912,10 +1912,13 @@ static int decode_header(EXRContext *s, AVFrame *frame) continue; } else if ((var_size = check_header_variable(s, "writer", "string", 1)) >= 0) { - uint8_t key[256] = { 0 }; + uint8_t *key = av_malloc(var_size); - bytestream2_get_buffer(gb, key, FFMIN(sizeof(key) - 1, var_size)); - av_dict_set(&metadata, "writer", key, 0); + if (!key) + return AVERROR(ENOMEM); + + bytestream2_get_buffer(gb, key, var_size); + av_dict_set(&metadata, "writer", key, AV_DICT_DONT_STRDUP_VAL); continue; } else if ((var_size = check_header_variable(s, "framesPerSecond", @@ -1937,9 +1940,12 @@ static int decode_header(EXRContext *s, AVFrame *frame) continue; } else if ((var_size = check_header_variable(s, "type", "string", 16)) >= 0) { - uint8_t key[256] = { 0 }; + uint8_t *key = av_malloc(var_size); + + if (!key) + return AVERROR(ENOMEM); - bytestream2_get_buffer(gb, key, FFMIN(sizeof(key) - 1, var_size)); + bytestream2_get_buffer(gb, key, var_size); if (strncmp("scanlineimage", key, var_size) && strncmp("tiledimage", key, var_size)) return AVERROR_PATCHWELCOME; @@ -1970,7 +1976,6 @@ static int decode_header(EXRContext *s, AVFrame *frame) { uint8_t name[256] = { 0 }; uint8_t type[256] = { 0 }; - uint8_t value[256] = { 0 }; int i = 0, size; while (bytestream2_get_bytes_left(gb) > 0 && @@ -1987,9 +1992,18 @@ static int decode_header(EXRContext *s, AVFrame *frame) bytestream2_skip(gb, 1); size = bytestream2_get_le32(gb); - bytestream2_get_buffer(gb, value, FFMIN(sizeof(value) - 1, size)); - if (!strcmp(type, "string")) - av_dict_set(&metadata, name, value, 0); + if (strcmp(type, "string") != 0) { + bytestream2_skip(gb, size); + + continue; + } + uint8_t *value = av_malloc(size); + + if (!value) + return AVERROR(ENOMEM); + + bytestream2_get_buffer(gb, value, size); + av_dict_set(&metadata, name, value, AV_DICT_DONT_STRDUP_VAL); } } -- 2.32.0 (Apple Git-132) _______________________________________________ ffmpeg-devel mailing list ffmpeg-devel@ffmpeg.org https://ffmpeg.org/mailman/listinfo/ffmpeg-devel To unsubscribe, visit link above, or email ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe".