diff --git a/ffmpeg-CVE-2023-50010.patch b/ffmpeg-CVE-2023-50010.patch index 6ddb999..5d78ab3 100644 --- a/ffmpeg-CVE-2023-50010.patch +++ b/ffmpeg-CVE-2023-50010.patch @@ -1,18 +1,20 @@ commit e4d2666bdc3dbd177a81bbf428654a5f2fa3787a (20231224_CVE-2023-50010_e4d2666bdc3dbd177a81bbf428654a5f2fa3787a) Author: Michael Niedermayer -Date: Sun Dec 24 20:50:51 2023 +0100 +Date: Sun Dec 24 20:50:51 2023 +0100 +References: CVE-2023-50010 +References: https://bugzilla.opensuse.org/1172424 - avfilter/vf_gradfun: Do not overread last line - - The code works in steps of 2 lines and lacks support for odd height - Implementing odd height support is better but for now this fixes the - out of array access - - Fixes: out of array access - Fixes: tickets/10702/poc6ffmpe - - Found-by: Zeng Yunxiang - Signed-off-by: Michael Niedermayer +avfilter/vf_gradfun: Do not overread last line + +The code works in steps of 2 lines and lacks support for odd height +Implementing odd height support is better but for now this fixes the +out of array access + +Fixes: out of array access +Fixes: tickets/10702/poc6ffmpe + +Found-by: Zeng Yunxiang +Signed-off-by: Michael Niedermayer diff -Nura ffmpeg-4.4.4/libavfilter/vf_gradfun.c ffmpeg-4.4.4_new/libavfilter/vf_gradfun.c --- ffmpeg-4.4.4/libavfilter/vf_gradfun.c 2023-04-13 02:01:50.000000000 +0800