Closed
Bug 506878
Opened 15 years ago
Closed 15 years ago
oggz_read_sync and oggz_read_update_gp don't check for errors from oggz_stream_get_content
Categories
(Core :: Audio/Video, defect)
Core
Audio/Video
Tracking
()
RESOLVED
FIXED
People
(Reporter: timeless, Assigned: cajbir)
References
(Blocks 1 open bug, )
Details
(Keywords: coverity, Whiteboard: [sg:moderate])
55 oggz_stream_get_content (OGGZ * oggz, long serialno) 62 if (stream == NULL) return OGGZ_ERR_BAD_SERIALNO; i'm aware that the code thinks its serial number is ok, but the function returns two error codes at this point and could potentially return more. it'd be appreciated if callers always checked for error values. 318 oggz_read_sync (OGGZ * oggz) 397 content = oggz_stream_get_content(oggz, serialno); 414 reader->current_granulepos = 415 oggz_auto_calculate_granulepos (content, granulepos, stream, op);
Summary: oggz_read_sync doesn't check for errors from oggz_stream_get_content → oggz_read_sync and oggz_read_update_gp don't check for errors from oggz_stream_get_content
Comment 1•15 years ago
|
||
Fixed in upstream commit 822b0af67199d97298261d615cf6a3a50a3b8426
Updated•15 years ago
|
Status: UNCONFIRMED → NEW
Ever confirmed: true
Whiteboard: [sg:moderate]
Comment 2•15 years ago
|
||
Fixed by liboggz update.
Updated•11 years ago
|
Group: core-security
Updated•6 years ago
|
Blocks: coverity-analysis
You need to log in
before you can comment on or make changes to this bug.
Description
•