diff options
author | Xi Wang <xi.wang@gmail.com> | 2013-01-22 21:40:05 -0500 |
---|---|---|
committer | Michael Niedermayer <michaelni@gmx.at> | 2013-09-22 22:34:14 +0200 |
commit | 8c0261d6859d06373593a914bbd300e2eaa414c9 (patch) | |
tree | 4c9559733a1237b0a1aa19de330b03b08c67aaa5 /tests/fate-update.sh | |
parent | 4b7036c1d9d16f015ce2f35773b6c4a30ae6488e (diff) | |
download | ffmpeg-8c0261d6859d06373593a914bbd300e2eaa414c9.tar.gz |
rtmp: fix buffer overflows in ff_amf_tag_contents()
A negative `size' will bypass FFMIN(). In the subsequent memcpy() call,
`size' will be considered as a large positive value, leading to a buffer
overflow.
Change the type of `size' to unsigned int to avoid buffer overflow, and
simplify overflow checks accordingly.
Signed-off-by: Xi Wang <xi.wang@gmail.com>
Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
(cherry picked from commit 4e692374f7962ea358c329de38c380103f8991b6)
Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
Diffstat (limited to 'tests/fate-update.sh')
0 files changed, 0 insertions, 0 deletions