commit
4c1360818fc8948e9307059fba4dc47ba8ad255d
Author: Aurelien David <aurelien.david@telecom-paristech.fr>
Date: Thu Dec 13 14:39:21 2018 +0100
Description: CVE-2018-20760
check error code on call to gf_utf8_wcstombs (#1177)
Gbp-Pq: Name CVE-2018-20760.patch
}
sptr = (u16 *)szLine;
i = (u32) gf_utf8_wcstombs(szLineConv, 1024, (const unsigned short **) &sptr);
+ if (i >= (u32)ARRAY_LENGTH(szLineConv))
+ return NULL;
szLineConv[i] = 0;
strcpy(szLine, szLineConv);
/*this is ugly indeed: since input is UTF16-LE, there are many chances the fgets never reads the \0 after a \n*/