[FFmpeg-devel] [PATCH 2/2] doc/examples/decode_video: Fix format string vulnerability

Michael Niedermayer michael at niedermayer.cc
Sat Apr 8 00:29:12 EEST 2017


Fixes: CID1404843

Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
---
 doc/examples/decode_video.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/doc/examples/decode_video.c b/doc/examples/decode_video.c
index 613bc5cc88..4377fd49e0 100644
--- a/doc/examples/decode_video.c
+++ b/doc/examples/decode_video.c
@@ -74,7 +74,7 @@ static void decode(AVCodecContext *dec_ctx, AVFrame *frame, AVPacket *pkt,
 
         /* the picture is allocated by the decoder. no need to
            free it */
-        snprintf(buf, sizeof(buf), filename, dec_ctx->frame_number);
+        snprintf(buf, sizeof(buf), "%s-%d", filename, dec_ctx->frame_number);
         pgm_save(frame->data[0], frame->linesize[0],
                  frame->width, frame->height, buf);
     }
-- 
2.11.0



More information about the ffmpeg-devel mailing list