diff options
author | Michael Niedermayer <michaelni@gmx.at> | 2006-05-13 11:37:56 +0000 |
---|---|---|
committer | Michael Niedermayer <michaelni@gmx.at> | 2006-05-13 11:37:56 +0000 |
commit | a443a2530d00b7019269202ac0f5ca8ba0a021c7 (patch) | |
tree | 9dfe3c9388c09a10ef32b64a871d3dac45495cb5 /libavformat/smacker.c | |
parent | 3a1a7e32ace7af47de74e8ae779cb4e04c89aa97 (diff) | |
download | ffmpeg-a443a2530d00b7019269202ac0f5ca8ba0a021c7.tar.gz |
sanity checks some might have been exploitable
Originally committed as revision 5370 to svn://svn.ffmpeg.org/ffmpeg/trunk
Diffstat (limited to 'libavformat/smacker.c')
-rw-r--r-- | libavformat/smacker.c | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/libavformat/smacker.c b/libavformat/smacker.c index 916dd84077..7733da3bd7 100644 --- a/libavformat/smacker.c +++ b/libavformat/smacker.c @@ -114,6 +114,13 @@ static int smacker_read_header(AVFormatContext *s, AVFormatParameters *ap) for(i = 0; i < 7; i++) smk->audio[i] = get_le32(pb); smk->treesize = get_le32(pb); + + if(smk->treesize >= UINT_MAX/4){ // smk->treesize + 16 must not overflow (this check is probably redundant) + av_log(s, AV_LOG_ERROR, "treesize too large\n"); + return -1; + } + +//FIXME remove extradata "rebuilding" smk->mmap_size = get_le32(pb); smk->mclr_size = get_le32(pb); smk->full_size = get_le32(pb); |