Commit 40922dead0 for ffmpeg
commit 40922dead061fbc9d27c6ec11d3b3b8a41511bbc
Author: Michael Niedermayer <michael@niedermayer.cc>
Date: Sun Oct 11 02:03:43 2026 +0200
avformat/dashenc: Use av_escape() in xmlescape()
The int based size computation of the open coded escaping overflows for
strings above about 1.4 GB, av_escape() checks the size.
Fixes: out of array write
Fixes: cu2EEgL7QRCV
Found during reviewt
diff --git a/libavformat/dashenc.c b/libavformat/dashenc.c
index 6b4ab8eeb9..ca8e5401c1 100644
--- a/libavformat/dashenc.c
+++ b/libavformat/dashenc.c
@@ -590,42 +590,10 @@ static void output_segment_list(OutputStream *os, AVIOContext *out, AVFormatCont
}
static char *xmlescape(const char *str) {
- int outlen = strlen(str)*3/2 + 6;
- char *out = av_realloc(NULL, outlen + 1);
- int pos = 0;
- if (!out)
+ char *out;
+ if (av_escape(&out, str, NULL, AV_ESCAPE_MODE_XML,
+ AV_ESCAPE_FLAG_XML_SINGLE_QUOTES | AV_ESCAPE_FLAG_XML_DOUBLE_QUOTES) < 0)
return NULL;
- for (; *str; str++) {
- if (pos + 6 > outlen) {
- char *tmp;
- outlen = 2 * outlen + 6;
- tmp = av_realloc(out, outlen + 1);
- if (!tmp) {
- av_free(out);
- return NULL;
- }
- out = tmp;
- }
- if (*str == '&') {
- memcpy(&out[pos], "&", 5);
- pos += 5;
- } else if (*str == '<') {
- memcpy(&out[pos], "<", 4);
- pos += 4;
- } else if (*str == '>') {
- memcpy(&out[pos], ">", 4);
- pos += 4;
- } else if (*str == '\'') {
- memcpy(&out[pos], "'", 6);
- pos += 6;
- } else if (*str == '\"') {
- memcpy(&out[pos], """, 6);
- pos += 6;
- } else {
- out[pos++] = *str;
- }
- }
- out[pos] = '\0';
return out;
}