From patchwork Thu May 12 15:30:19 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: vectronic X-Patchwork-Id: 35747 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a05:6a20:a885:b0:7f:4be2:bd17 with SMTP id ca5csp507235pzb; Thu, 12 May 2022 08:31:12 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxt6sq1OCghFNpkfbRR4nPNPG02ubXXLkuno4yX95wCqMdFTgN1Jq9eRzpGoBbkluuXa4n0 X-Received: by 2002:a05:6402:1113:b0:428:679e:f73f with SMTP id u19-20020a056402111300b00428679ef73fmr33911502edv.378.1652369472477; Thu, 12 May 2022 08:31:12 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1652369472; cv=none; d=google.com; s=arc-20160816; b=VTp1qbA+WJfN5l/birm5ODPRV8QrAh7nJpGFPkdEiZTEHm2IJNY+hqPmyYvwBnqHxQ lRlkpVHhT9+DGNBgk7w2AMF8UsJrKmN9TedW7864RLmSQlRbC6gvBhHa7Bbyw9aLaPq/ KgREpegnO1CRz30pYdP0VC/U0YNRxVuf9L1S3QxKry18dtskHdc5/5ibdPd9CAwl4CsB 6FIRhGuT3ZUnwv5Ntig8LGO+jknurpN04u7NOnpLOnUPmBF/ma+clYEPYu97GO9FX/K5 fH1c7+t5ZXLrpf9KlwsqHQGbsEsvS/+aIMH96v+Q+/Dw3fBQm8MioUbjfsR+3a7p87u5 SxUQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:content-transfer-encoding:cc:reply-to :list-subscribe:list-help:list-post:list-archive:list-unsubscribe :list-id:precedence:subject:mime-version:references:in-reply-to :message-id:date:to:from:dkim-signature:delivered-to; bh=0zI4DeNsyR9QHWCJZ2ygvpQrThwpzyjx/A5FmR0IseM=; b=esoWoxkVkkVzPK4oBIo94N65MHp2iVshY+qPJ21QgIhoFJVNk6S/9cOYnuK0Bl4XMQ wZ5C11iSWc/Cw+Jnt1fBtwY254cnijrv8sScFd5kY7LokOQJF/ppMhVaq4wJDbs06071 lmL23ws2RkQ4kgzw+XImYQ2FzNTAuknJWLDM8SgbMEs5Qonx3Kc15ramWjChxhdwWOLp zqgJ/LavgvB5sHyZNV0KaLe+ryhqzrvZFVisvJHiREwfs/XU4njbyMB76HJ13M6SM/Tn S6hkQm8wn4MgA3ZD9yd8cYkrdHqPFC0e7lixYw1udhAdd91Hx69ZoJ31qMllHOyT0LLb zx4g== ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20210112 header.b="HX/UVTMr"; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id sh16-20020a1709076e9000b006fa7f144ac3si6821246ejc.3.2022.05.12.08.31.11; Thu, 12 May 2022 08:31:12 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20210112 header.b="HX/UVTMr"; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 1280568B465; Thu, 12 May 2022 18:30:56 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from mail-wm1-f45.google.com (mail-wm1-f45.google.com [209.85.128.45]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id AC0EB68B3CF for ; Thu, 12 May 2022 18:30:49 +0300 (EEST) Received: by mail-wm1-f45.google.com with SMTP id r188-20020a1c44c5000000b003946c466c17so2737624wma.4 for ; Thu, 12 May 2022 08:30:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=CfV91yG3g9P8ALHqlNrUxdASF6SNyKzb9TLxmqTmJXc=; b=HX/UVTMrIVDiwD8hqNIPIaiuim4b+YC8vlzSR0WmqSpZj+MTMFbTA3DQXgTLBOReQn di3qXDpyp7lZ56G2a5W4MFQ0zn+EaeC/58mfCxCz5/VEb5VlmZpS8PCbQgauk8M12kvL 8jHXZaFd3RQRk8kwOr0CmdJCi3vOiy3GI3cIMJq4Re30qpCaundwgWS8uiJPwZkjBXPk PCiQzh+rLS0yJHImqk7OTWtXzVQXk8VLXgJrfc6SJ3dtEkiJukkQ5EKks/V13R6FYx81 sU5qEPRVLsBGMbkQE2+PvHpNsZa2fKQdLJcZmQSziTWx5JKRTMGBAdKa6zzPS9LpruD5 EHnQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=CfV91yG3g9P8ALHqlNrUxdASF6SNyKzb9TLxmqTmJXc=; b=GjhayAHXeeJ+ifDFq6Wk8mQfZc7t3faDZRx1mrGwSgJx/ZcUHMreXZP0rZqRUj1nNe /NlkmDtqGZA7sfRWf3JZCNQGw535UmdYl3uXm2OngCX8bdWBhC3zNKRfyksdtCZTHPb2 R0mN+3rp5mSEWH9RGl12STWZi5fd1315AyQyzFXAQKwFpyewaUyi7AalUERGozKM7IFn XLKHI8n2u52V4EqAxOX/5ml6q4i7N3ai3O9kU7dZOY7BLaePecBeP4haFvCIiFP3qLd7 0nDb/OiGg7NLQJceFMrOFB4dI8w6CeWSpDvFUw7CV7rJOCqSGN+GDed+OlCGUPTJy+8d 3DIA== X-Gm-Message-State: AOAM533Yevd4X+538RIF6gdKrKNYFqOJTeR7V+wT5xBrzHY3KlwsFnRA qoliNCi/H8Lk3gImUSm5agnRI1TFDcOUbA== X-Received: by 2002:a05:600c:154d:b0:394:8d64:9166 with SMTP id f13-20020a05600c154d00b003948d649166mr390078wmg.102.1652369449156; Thu, 12 May 2022 08:30:49 -0700 (PDT) Received: from localhost.localdomain ([79.173.135.242]) by smtp.gmail.com with ESMTPSA id y25-20020a1c4b19000000b0039489e1bbd6sm2806793wma.47.2022.05.12.08.30.48 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 12 May 2022 08:30:48 -0700 (PDT) From: vectronic To: ffmpeg-devel@ffmpeg.org Date: Thu, 12 May 2022 16:30:19 +0100 Message-Id: <20220512153019.66066-2-hello.vectronic@gmail.com> X-Mailer: git-send-email 2.32.0 (Apple Git-132) In-Reply-To: <20220512153019.66066-1-hello.vectronic@gmail.com> References: <20220512153019.66066-1-hello.vectronic@gmail.com> MIME-Version: 1.0 Subject: [FFmpeg-devel] [PATCH 1/1] fix: use declared size for attribute of type string to ensure full value used and prevent parse failure for string lengths longer than 256 X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Cc: vectronic Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: iZUqc7ElbzJn Signed-off-by: vectronic --- libavcodec/exr.c | 32 +++++++++++++++++++++++--------- 1 file changed, 23 insertions(+), 9 deletions(-) diff --git a/libavcodec/exr.c b/libavcodec/exr.c index 8cd867a32f..bc2afcee53 100644 --- a/libavcodec/exr.c +++ b/libavcodec/exr.c @@ -1912,10 +1912,13 @@ static int decode_header(EXRContext *s, AVFrame *frame) continue; } else if ((var_size = check_header_variable(s, "writer", "string", 1)) >= 0) { - uint8_t key[256] = { 0 }; + uint8_t *key = av_malloc(var_size); - bytestream2_get_buffer(gb, key, FFMIN(sizeof(key) - 1, var_size)); - av_dict_set(&metadata, "writer", key, 0); + if (!key) + return AVERROR(ENOMEM); + + bytestream2_get_buffer(gb, key, var_size); + av_dict_set(&metadata, "writer", key, AV_DICT_DONT_STRDUP_VAL); continue; } else if ((var_size = check_header_variable(s, "framesPerSecond", @@ -1937,9 +1940,12 @@ static int decode_header(EXRContext *s, AVFrame *frame) continue; } else if ((var_size = check_header_variable(s, "type", "string", 16)) >= 0) { - uint8_t key[256] = { 0 }; + uint8_t *key = av_malloc(var_size); + + if (!key) + return AVERROR(ENOMEM); - bytestream2_get_buffer(gb, key, FFMIN(sizeof(key) - 1, var_size)); + bytestream2_get_buffer(gb, key, var_size); if (strncmp("scanlineimage", key, var_size) && strncmp("tiledimage", key, var_size)) return AVERROR_PATCHWELCOME; @@ -1970,7 +1976,6 @@ static int decode_header(EXRContext *s, AVFrame *frame) { uint8_t name[256] = { 0 }; uint8_t type[256] = { 0 }; - uint8_t value[256] = { 0 }; int i = 0, size; while (bytestream2_get_bytes_left(gb) > 0 && @@ -1987,9 +1992,18 @@ static int decode_header(EXRContext *s, AVFrame *frame) bytestream2_skip(gb, 1); size = bytestream2_get_le32(gb); - bytestream2_get_buffer(gb, value, FFMIN(sizeof(value) - 1, size)); - if (!strcmp(type, "string")) - av_dict_set(&metadata, name, value, 0); + if (strcmp(type, "string") != 0) { + bytestream2_skip(gb, size); + + continue; + } + uint8_t *value = av_malloc(size); + + if (!value) + return AVERROR(ENOMEM); + + bytestream2_get_buffer(gb, value, size); + av_dict_set(&metadata, name, value, AV_DICT_DONT_STRDUP_VAL); } }