aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorDale Curtis <dalecurtis@chromium.org>2015-01-05 16:34:17 -0800
committerMichael Niedermayer <michaelni@gmx.at>2015-01-09 17:19:10 +0100
commit0ce35b8ce8b9e06a4dedc62b4fe10261db67f0a3 (patch)
tree7e062410d13082048af0eaf6562206080adae51e
parent25312a427bda360a98c6a38be7af9e5f686c9902 (diff)
downloadffmpeg-0ce35b8ce8b9e06a4dedc62b4fe10261db67f0a3.tar.gz
mov: Fix negative size calculation in mov_read_default().
The previous code assumed if an atom was marked with a 64-bit size extension, it actually had that data available. The new code verfies there's enough data in the atom for this to be done. Failure to verify causes total_size > atom.size which will result in negative size calculations later on. Found-by: Paul Mehta <paul@paulmehta.com> Signed-off-by: Dale Curtis <dalecurtis@chromium.org> Signed-off-by: Michael Niedermayer <michaelni@gmx.at> (cherry picked from commit 3ebd76a9c57558e284e94da367dd23b435e6a6d0) Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
-rw-r--r--libavformat/mov.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/libavformat/mov.c b/libavformat/mov.c
index 11fdcf0194..47f0073df0 100644
--- a/libavformat/mov.c
+++ b/libavformat/mov.c
@@ -3431,7 +3431,7 @@ static int mov_read_default(MOVContext *c, AVIOContext *pb, MOVAtom atom)
}
}
total_size += 8;
- if (a.size == 1) { /* 64 bit extended size */
+ if (a.size == 1 && total_size + 8 <= atom.size) { /* 64 bit extended size */
a.size = avio_rb64(pb) - 8;
total_size += 8;
}