Module: libav Branch: release/9 Commit: 9680f84a31fa97272777e43a9234eb20d6da5930
Author: Martin Storsjö <[email protected]> Committer: Luca Barbato <[email protected]> Date: Mon Jul 15 11:28:46 2013 +0300 ac3dec: Don't consume more data than the actual input packet size This was handled properly in the normal return case at the end of the function, but not in this special case. Returning a value larger than the input packet size can cause problems for certain library users. Returning the actual input buffer size unconditionally, since it is not guaranteed that frame_size is set to a sensible value at this point. Cc: [email protected] Signed-off-by: Martin Storsjö <[email protected]> (cherry picked from commit 8f24c12be7a3b3ea105e67bba9a867fe210a2333) Signed-off-by: Luca Barbato <[email protected]> --- libavcodec/ac3dec.c | 2 +- 1 files changed, 1 insertions(+), 1 deletions(-) diff --git a/libavcodec/ac3dec.c b/libavcodec/ac3dec.c index 6fb7b0b..4f32c2d 100644 --- a/libavcodec/ac3dec.c +++ b/libavcodec/ac3dec.c @@ -1308,7 +1308,7 @@ static int ac3_decode_frame(AVCodecContext * avctx, void *data, av_log(avctx, AV_LOG_ERROR, "unsupported frame type : " "skipping frame\n"); *got_frame_ptr = 0; - return s->frame_size; + return buf_size; } else { av_log(avctx, AV_LOG_ERROR, "invalid frame type\n"); } _______________________________________________ libav-commits mailing list [email protected] https://lists.libav.org/mailman/listinfo/libav-commits
