#960: Added a Buffer Overflow Fix in INFO tags of RIFFVIDEO.CPP

v0.27.3
Abhinav Badola 11 years ago
parent 8706e16874
commit 09fd874c99

@ -856,7 +856,7 @@ namespace Exiv2 {
void RiffVideo::infoTagsHandler() void RiffVideo::infoTagsHandler()
{ {
const long bufMinSize = 100; const long bufMinSize = 10000;
DataBuf buf(bufMinSize); DataBuf buf(bufMinSize);
buf.pData_[4] = '\0'; buf.pData_[4] = '\0';
io_->seek(-12, BasicIo::cur); io_->seek(-12, BasicIo::cur);
@ -879,10 +879,14 @@ namespace Exiv2 {
if(infoSize >= 0) { if(infoSize >= 0) {
size -= infoSize; size -= infoSize;
io_->read(buf.pData_, infoSize); io_->read(buf.pData_, infoSize);
if(infoSize < 4)
buf.pData_[infoSize] = '\0';
} }
if(tv) if(tv)
xmpData_[exvGettext(tv->label_)] = buf.pData_; xmpData_[exvGettext(tv->label_)] = buf.pData_;
else
continue;
} }
io_->seek(cur_pos + size_external, BasicIo::beg); io_->seek(cur_pos + size_external, BasicIo::beg);
} // RiffVideo::infoTagsHandler } // RiffVideo::infoTagsHandler

Loading…
Cancel
Save