Module: libav Branch: master Commit: 0aaa85dbedbd4029dac0e78f10a412c7ec9a0d4d
Author: Justin Ruggles <[email protected]> Committer: Justin Ruggles <[email protected]> Date: Mon Oct 17 10:22:46 2011 -0400 nellymoserdec: fail if output buffer is too small avoids silently truncating the output --- libavcodec/nellymoserdec.c | 6 +++++- 1 files changed, 5 insertions(+), 1 deletions(-) diff --git a/libavcodec/nellymoserdec.c b/libavcodec/nellymoserdec.c index ec045af..3812d78 100644 --- a/libavcodec/nellymoserdec.c +++ b/libavcodec/nellymoserdec.c @@ -176,8 +176,12 @@ static int decode_tag(AVCodecContext * avctx, return buf_size; } block_size = NELLY_SAMPLES * av_get_bytes_per_sample(avctx->sample_fmt); - blocks = FFMIN(buf_size / NELLY_BLOCK_LEN, *data_size / block_size); + blocks = buf_size / NELLY_BLOCK_LEN; if (blocks <= 0) { + av_log(avctx, AV_LOG_ERROR, "Packet is too small\n"); + return AVERROR_INVALIDDATA; + } + if (*data_size < blocks * block_size) { av_log(avctx, AV_LOG_ERROR, "Output buffer is too small\n"); return AVERROR(EINVAL); } _______________________________________________ libav-commits mailing list [email protected] https://lists.libav.org/mailman/listinfo/libav-commits
