Badly formed files can cause `create_sample_table()` to OOM.
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Anfängerfreundlichkeit
- 25/100
Rechercherichtung
Beginne damit, create_sample_table() und die Verarbeitung der stsc- und stsz-Boxen nachzuverfolgen, und prüfe anschließend, wie get_indices geparste Daten bereitstellt. Vergleiche die Fehlerszenarien aus Gecko Bugs 1661368 und 1814791, einschließlich nicht übereinstimmender oder übergroßer Sample-Anzahlen. Erledigt ist die Aufgabe, wenn verhindert wird, dass fehlerhafte Dateien eine beliebige Allokation oder OOM verursachen, während das Parsen gültiger Dateien erhalten bleibt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
See Gecko Bug 1661368 and more recently Bug 1814791.
There is currently no validation of whether a file with an stsc box with a large sample count is actually referencing offsets that fall within the file, which allows create_sample_table() to allocate an arbitrarily large vector and OOM.
We could just set a configurable hard limit on the number of samples it can allocate, but I don't know if that's the best solution.
We can also fail early when the relevant sample boxes have mismatched sample counts, but I'm not sure if there are files that currently parse and break that rule, and as tnikkel pointed out, the fuzzer may still find a way to create a matching sample count that causes OOM. Might still be worth implementing this if it makes sense to fail that way.
I think the most ideal solution is instead to make create_sample_table() aware of the amount of data in the file that is currently available to the caller, and use the stsz box to determine how many samples the vector needs to allocate to reach EOF. For cases where the full size is not known beforehand, API users would have to call get_indices multiple times and be aware that their pointers will be invalid, but that doesn't seem like a difficult problem.
What I wonder is whether the available data is something that should be accessible from other parts of mp4parse as well, for example to allow the box parsing to indicate that it hit the end of the available data but can continue parsing when more data is available.
Feel free to let me know if this idea doesn't make sense, we can use this issue to brainstorm more solutions if necessary.
- Vorherrschende Sprache
- Rust
- Sterne
- 448
- Forks
- 72
- Ø Merge
- 6 T. 4 Std.
- Gemergte PRs (30 T.)
- 1
Entwicklungsumgebung
Die Einrichtungsdateien dieses Projekts haben wir noch nicht geprüft. Beginnen Sie mit der README; die allgemeinen Schritte stehen in unserem Leitfaden für den ersten Beitrag.
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus mozilla/mp4parse-rust
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 48/100
mozilla/mp4parse-rust#444 · 5 Kommentare ·
-
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 45/100
mozilla/mp4parse-rust#441 ·
-
senc boxOffen
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 15/100
mozilla/mp4parse-rust#415 ·
-
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 28/100
mozilla/mp4parse-rust#414 · 4 Kommentare ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 35/100
mozilla/mp4parse-rust#412 · 2 Kommentare ·
Alle Issues in mozilla/mp4parse-rust
Ähnliche Issues
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
stellar/stellar-cli#2773 ·
Maintainer antworten meist innerhalb von 2 Tagen
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 85/100
voidzero-dev/oxc-angular-compiler#511 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 1/5 1-3 Stunden Anfängerfreundlichkeit 86/100
yantrikos/yantrik-os#539 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
Maintainer antworten meist innerhalb von 1 Tag
-
documentation station:mac ui-dashboard
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 86/100
rolter-ai/rolter#2490 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag