1
0
mirror of https://github.com/FFmpeg/FFmpeg.git synced 2025-03-17 20:17:55 +02:00

rsd: limit number of channels

Negative values don't make sense and too large values can cause
overflows. For AV_CODEC_ID_ADPCM_THP this leads to a too small extradata
buffer being allocated, causing out-of-bounds writes.

Reviewed-by: Michael Niedermayer <michael@niedermayer.cc>
Signed-off-by: Andreas Cadhalpun <Andreas.Cadhalpun@googlemail.com>
(cherry picked from commit ee5f0f1d355fa0fd9194ac97a2c8598c93ed328b)
Signed-off-by: Andreas Cadhalpun <Andreas.Cadhalpun@googlemail.com>
This commit is contained in:
Andreas Cadhalpun 2016-10-19 23:40:41 +02:00
parent 0496403c08
commit 45b18fbb9a

View File

@ -84,8 +84,10 @@ static int rsd_read_header(AVFormatContext *s)
}
codec->channels = avio_rl32(pb);
if (!codec->channels)
if (codec->channels <= 0 || codec->channels > INT_MAX / 36) {
av_log(s, AV_LOG_ERROR, "Invalid number of channels: %d\n", codec->channels);
return AVERROR_INVALIDDATA;
}
avio_skip(pb, 4); // Bit depth
codec->sample_rate = avio_rl32(pb);