mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2025-01-24 13:56:33 +02:00
flvdec: Check for overflow before allocating arrays
On allocation, the array length is multiplied by sizeof(int64_t), this prevents the multiplication from overflowing. Signed-off-by: Martin Storsjö <martin@martin.st>
This commit is contained in:
parent
9b921a8272
commit
a246cefa75
@ -161,6 +161,9 @@ static int parse_keyframes_index(AVFormatContext *s, AVIOContext *ioc, AVStream
|
||||
break;
|
||||
|
||||
arraylen = avio_rb32(ioc);
|
||||
if (arraylen >> 28)
|
||||
break;
|
||||
|
||||
/*
|
||||
* Expect only 'times' or 'filepositions' sub-arrays in other case refuse to use such metadata
|
||||
* for indexing
|
||||
|
Loading…
x
Reference in New Issue
Block a user