https://github.com/videolan/vlc/search?utf8=%E2%9C%93&q=subt...
https://github.com/videolan/vlc/search?utf8=%E2%9C%93&q=subt...
> Fix potential heap buffer overflow
> Fix potential out of bound read
> Fix invalid double increment.
The exploit would presumably involve structuring your data so that the excess increment skips over a terminator of some sort. If it's scanning until it hits a zero byte, and you get it to skip over the zero byte, then you have a buffer overflow.
Do we have to build it from source?
Maybe we should stop random people from contributing to complex C projects?
The problem is that boring stuff can also be very security sensitive.
Yes I do, this is internet after all!
> seems you know your stuff,
Now you lost me :)
I wish :)
All those projects are under-funded, done by volunteers, on countless platforms, doing very low-level stuff, and supporting many formats.
This has nothing to do with one project or another.
(*(psz_text + 1 ) ) == '~'
when you can instead write psz_text[1] == '~'
Fewer tokens means less overhead for the human reader, and that asterisk-and-add pattern is exactly what the bracket array indexing operator does, so why not use it? This is one of my many C pet peeves, heh.Also on a more personal note, if you're going to be putting things inside parentheses with whitespace, make it symmetrical.