CVE-2017-9993
authorMarkus Koschany <apo@debian.org>
Sun, 30 Dec 2018 15:57:18 +0000 (16:57 +0100)
committerMike Gabriel <sunweaver@debian.org>
Sat, 30 Mar 2019 20:44:13 +0000 (20:44 +0000)
Origin: https://github.com/FFmpeg/FFmpeg/commit/a5d849b149ca67ced2d271dc84db0bc95a548abb

Gbp-Pq: Name CVE-2017-9993.patch

libavformat/avidec.c

index 928bbaaf69b20649e53d580ca2ae8f3e7b59a7b8..713f82258d7bd487d0c088226a944dc4e712c552 100644 (file)
@@ -870,6 +870,9 @@ static int read_gab2_sub(AVStream *st, AVPacket *pkt)
         if (!(sub_demuxer = av_probe_input_format2(&pd, 1, &score)))
             goto error;
 
+        if (strcmp(sub_demuxer->name, "srt") && strcmp(sub_demuxer->name, "ass"))
+            goto error;
+
         if (!(ast->sub_ctx = avformat_alloc_context()))
             goto error;