aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorAndreas Cadhalpun <Andreas.Cadhalpun@googlemail.com>2016-10-19 23:40:41 +0200
committerAndreas Cadhalpun <Andreas.Cadhalpun@googlemail.com>2016-11-27 00:28:02 +0100
commit13f032abbb26c7b47d700745f7ace05375eae34f (patch)
tree5e7edfadb8b8638ce9f2f00b76ecd0de2d5a7919
parentd69dc10466e234c0e4ff9cb7e4d0e5d63ceeb357 (diff)
downloadffmpeg-13f032abbb26c7b47d700745f7ace05375eae34f.tar.gz
rsd: limit number of channels
Negative values don't make sense and too large values can cause overflows. For AV_CODEC_ID_ADPCM_THP this leads to a too small extradata buffer being allocated, causing out-of-bounds writes. Reviewed-by: Michael Niedermayer <michael@niedermayer.cc> Signed-off-by: Andreas Cadhalpun <Andreas.Cadhalpun@googlemail.com> (cherry picked from commit ee5f0f1d355fa0fd9194ac97a2c8598c93ed328b) Signed-off-by: Andreas Cadhalpun <Andreas.Cadhalpun@googlemail.com>
-rw-r--r--libavformat/rsd.c4
1 files changed, 3 insertions, 1 deletions
diff --git a/libavformat/rsd.c b/libavformat/rsd.c
index ee6fdfbeb1..5a56e72bb3 100644
--- a/libavformat/rsd.c
+++ b/libavformat/rsd.c
@@ -84,8 +84,10 @@ static int rsd_read_header(AVFormatContext *s)
}
par->channels = avio_rl32(pb);
- if (!par->channels)
+ if (par->channels <= 0 || par->channels > INT_MAX / 36) {
+ av_log(s, AV_LOG_ERROR, "Invalid number of channels: %d\n", par->channels);
return AVERROR_INVALIDDATA;
+ }
avio_skip(pb, 4); // Bit depth
par->sample_rate = avio_rl32(pb);