[PATCH] sgpd box entry: disallow null grouping_type (#2389)
authorAurelien David <aurelien.david@telecom-paristech.fr>
Wed, 8 Feb 2023 15:52:00 +0000 (16:52 +0100)
committerMoritz Mühlenhoff <jmm@debian.org>
Mon, 19 Jun 2023 21:46:06 +0000 (22:46 +0100)
Gbp-Pq: Name CVE-2023-0760.patch

src/isomedia/box_code_base.c

index 968ead0a2c848040a1e9d0572dcacc8e1b177ba8..69755e2183f8dd88685e12639db1103aba8e2644 100644 (file)
@@ -9593,6 +9593,9 @@ static void *sgpd_parse_entry(u32 grouping_type, GF_BitStream *bs, u32 entry_siz
        case GF_ISOM_SAMPLE_GROUP_LBLI:
                entry_size = 2;
                break;
+       case 0:
+               GF_LOG(GF_LOG_WARNING, GF_LOG_CONTAINER, ("[iso file] sgpd entry null grouping_type is invalid\n") );
+               return NULL;
        default:
                break;
        }