[PATCH] fixed #1912
authorjeanlf <jeanlf@github.com>
Thu, 9 Sep 2021 13:04:12 +0000 (15:04 +0200)
committerAron Xu <aron@debian.org>
Tue, 23 May 2023 11:53:25 +0000 (12:53 +0100)
Gbp-Pq: Name CVE-2021-41459.patch

src/filters/dmx_nhml.c

index bbb5130e511bf4153c873560745d2624d2a6fd0c..084339f8a003f86fac6c49ba90ec34afdc039fda 100644 (file)
@@ -1021,8 +1021,14 @@ static GF_Err nhmldmx_send_sample(GF_Filter *filter, GF_NHMLDmxCtx *ctx)
                                        }
                                }
                        }
-                       else if (!stricmp(att->name, "xmlFrom")) strcpy(szXmlFrom, att->value);
-                       else if (!stricmp(att->name, "xmlTo")) strcpy(szXmlTo, att->value);
+                       else if (!stricmp(att->name, "xmlFrom")) {
+                               strncpy(szXmlFrom, att->value, 999);
+                               szXmlFrom[999]=0;
+                       }
+                       else if (!stricmp(att->name, "xmlTo")) {
+                               strncpy(szXmlTo, att->value, 999);
+                               szXmlTo[999]=0;
+                       }
                        /*DIMS flags*/
                        else if (!stricmp(att->name, "is-Scene") && !stricmp(att->value, "yes"))
                                dims_flags |= GF_DIMS_UNIT_S;