From 980207af3f25c2710401d2139d7c00114f2262d9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Gabriel=20Falc=C3=A3o?= Date: Sat, 14 Oct 2023 00:09:46 +0000 Subject: [PATCH] chore/CVE-2023-5217: brings in more buffer-overflow mitigation IOW: synchronizes lines of Track::Info::CopyStr from upstream - nothing new --- third_party/libwebm/mkvparser/mkvparser.cc | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/third_party/libwebm/mkvparser/mkvparser.cc b/third_party/libwebm/mkvparser/mkvparser.cc index 868afcb3ed0..35b4762994c 100644 --- a/third_party/libwebm/mkvparser/mkvparser.cc +++ b/third_party/libwebm/mkvparser/mkvparser.cc @@ -4569,7 +4569,8 @@ int Track::Info::CopyStr(char* Info::*str, Info& dst_) const { if (dst == NULL) return -1; - strcpy(dst, src); + memcpy(dst, src, len); + dst[len] = '\0'; return 0; }