Explicit backward compatible PS signalling is only possible if the
size of the audio specific config is known. This is not the case for
audioMuxVersion == 0 in LATM. Add a parameter to
avpriv_mpeg4audio_get_config() to prevent reading data past the
audio specific config in LATM.
---
 libavcodec/aacdec.c       |   24 ++++++++++++++++--------
 libavcodec/alsdec.c       |    2 +-
 libavcodec/mpeg4audio.c   |    4 ++--
 libavcodec/mpeg4audio.h   |    4 +++-
 libavcodec/mpegaudiodec.c |    2 +-
 libavformat/adtsenc.c     |    2 +-
 libavformat/flvdec.c      |    2 +-
 libavformat/isom.c        |    2 +-
 libavformat/latmenc.c     |    2 +-
 libavformat/matroskaenc.c |    2 +-
 10 files changed, 28 insertions(+), 18 deletions(-)

diff --git a/libavcodec/aacdec.c b/libavcodec/aacdec.c
index 37ccd18..374616e 100644
--- a/libavcodec/aacdec.c
+++ b/libavcodec/aacdec.c
@@ -454,13 +454,15 @@ static int decode_ga_specific_config(AACContext *ac, 
AVCodecContext *avctx,
  * @param   m4ac        pointer to MPEG4AudioConfig, used for parsing
  * @param   data        pointer to AVCodecContext extradata
  * @param   data_size   size of AVCCodecContext extradata
+ * @param   ebc_ps      explicit backward compatible PS
  *
  * @return  Returns error status or number of consumed bits. <0 - error
  */
 static int decode_audio_specific_config(AACContext *ac,
                                         AVCodecContext *avctx,
                                         MPEG4AudioConfig *m4ac,
-                                        const uint8_t *data, int data_size)
+                                        const uint8_t *data, int data_size,
+                                        int ebc_ps)
 {
     GetBitContext gb;
     int i;
@@ -472,7 +474,7 @@ static int decode_audio_specific_config(AACContext *ac,
 
     init_get_bits(&gb, data, data_size * 8);
 
-    if ((i = avpriv_mpeg4audio_get_config(m4ac, data, data_size)) < 0)
+    if ((i = avpriv_mpeg4audio_get_config(m4ac, data, data_size, ebc_ps)) < 0)
         return -1;
     if (m4ac->sampling_index > 12) {
         av_log(avctx, AV_LOG_ERROR, "invalid sampling rate index %d\n", 
m4ac->sampling_index);
@@ -572,7 +574,7 @@ static av_cold int aac_decode_init(AVCodecContext *avctx)
     if (avctx->extradata_size > 0) {
         if (decode_audio_specific_config(ac, ac->avctx, &ac->m4ac,
                                          avctx->extradata,
-                                         avctx->extradata_size) < 0)
+                                         avctx->extradata_size, 1) < 0)
             return -1;
     } else {
         int sr, i;
@@ -2309,12 +2311,18 @@ static inline uint32_t latm_get_value(GetBitContext *b)
 }
 
 static int latm_decode_audio_specific_config(struct LATMContext *latmctx,
-                                             GetBitContext *gb)
+                                             GetBitContext *gb, int asclen)
 {
     AVCodecContext *avctx = latmctx->aac_ctx.avctx;
     MPEG4AudioConfig m4ac;
     int  config_start_bit = get_bits_count(gb);
     int     bits_consumed, esize;
+    int ebc_ps = 1;
+
+    if (!asclen) {
+        ebc_ps = 0;
+        asclen = get_bits_left(gb);
+    }
 
     if (config_start_bit % 8) {
         av_log_missing_feature(latmctx->aac_ctx.avctx, "audio specific "
@@ -2324,7 +2332,7 @@ static int latm_decode_audio_specific_config(struct 
LATMContext *latmctx,
         bits_consumed =
             decode_audio_specific_config(NULL, avctx, &m4ac,
                                          gb->buffer + (config_start_bit / 8),
-                                         get_bits_left(gb) / 8);
+                                         asclen / 8, ebc_ps);
 
         if (bits_consumed < 0)
             return AVERROR_INVALIDDATA;
@@ -2382,11 +2390,11 @@ static int read_stream_mux_config(struct LATMContext 
*latmctx,
 
         // for all but first stream: use_same_config = get_bits(gb, 1);
         if (!audio_mux_version) {
-            if ((ret = latm_decode_audio_specific_config(latmctx, gb)) < 0)
+            if ((ret = latm_decode_audio_specific_config(latmctx, gb, 0)) < 0)
                 return ret;
         } else {
             int ascLen = latm_get_value(gb);
-            if ((ret = latm_decode_audio_specific_config(latmctx, gb)) < 0)
+            if ((ret = latm_decode_audio_specific_config(latmctx, gb, ascLen)) 
< 0)
                 return ret;
             ascLen -= ret;
             skip_bits_long(gb, ascLen);
@@ -2511,7 +2519,7 @@ static int latm_decode_frame(AVCodecContext *avctx, void 
*out, int *out_size,
         } else {
             if ((err = decode_audio_specific_config(
                     &latmctx->aac_ctx, avctx, &latmctx->aac_ctx.m4ac,
-                    avctx->extradata, avctx->extradata_size)) < 0)
+                    avctx->extradata, avctx->extradata_size, 1)) < 0)
                 return err;
             latmctx->initialized = 1;
         }
diff --git a/libavcodec/alsdec.c b/libavcodec/alsdec.c
index e7a0de2..f2b6926 100644
--- a/libavcodec/alsdec.c
+++ b/libavcodec/alsdec.c
@@ -290,7 +290,7 @@ static av_cold int read_specific_config(ALSDecContext *ctx)
     init_get_bits(&gb, avctx->extradata, avctx->extradata_size * 8);
 
     config_offset = avpriv_mpeg4audio_get_config(&m4ac, avctx->extradata,
-                                             avctx->extradata_size);
+                                                 avctx->extradata_size, 1);
 
     if (config_offset < 0)
         return -1;
diff --git a/libavcodec/mpeg4audio.c b/libavcodec/mpeg4audio.c
index f9e866f..f91fa29 100644
--- a/libavcodec/mpeg4audio.c
+++ b/libavcodec/mpeg4audio.c
@@ -76,7 +76,7 @@ static inline int get_sample_rate(GetBitContext *gb, int 
*index)
         avpriv_mpeg4audio_sample_rates[*index];
 }
 
-int avpriv_mpeg4audio_get_config(MPEG4AudioConfig *c, const uint8_t *buf, int 
buf_size)
+int avpriv_mpeg4audio_get_config(MPEG4AudioConfig *c, const uint8_t *buf, int 
buf_size, int ebc_ps)
 {
     GetBitContext gb;
     int specific_config_bitindex;
@@ -117,7 +117,7 @@ int avpriv_mpeg4audio_get_config(MPEG4AudioConfig *c, const 
uint8_t *buf, int bu
             return -1;
     }
 
-    if (c->ext_object_type != AOT_SBR) {
+    if (c->ext_object_type != AOT_SBR && ebc_ps) {
         while (get_bits_left(&gb) > 15) {
             if (show_bits(&gb, 11) == 0x2b7) { // sync extension
                 get_bits(&gb, 11);
diff --git a/libavcodec/mpeg4audio.h b/libavcodec/mpeg4audio.h
index d6730b9..0ece27f 100644
--- a/libavcodec/mpeg4audio.h
+++ b/libavcodec/mpeg4audio.h
@@ -47,9 +47,11 @@ extern const uint8_t ff_mpeg4audio_channels[8];
  * @param[in] c        MPEG4AudioConfig structure to fill.
  * @param[in] buf      Extradata from container.
  * @param[in] buf_size Extradata size.
+ * @param[in] ebc_ps   explicit backward compatible PS signalling might be used
  * @return On error -1 is returned, on success AudioSpecificConfig bit index 
in extradata.
  */
-int avpriv_mpeg4audio_get_config(MPEG4AudioConfig *c, const uint8_t *buf, int 
buf_size);
+int avpriv_mpeg4audio_get_config(MPEG4AudioConfig *c, const uint8_t *buf,
+                                 int buf_size, int ebc_ps);
 
 enum AudioObjectType {
     AOT_NULL,
diff --git a/libavcodec/mpegaudiodec.c b/libavcodec/mpegaudiodec.c
index e3d19c0..8002e20 100644
--- a/libavcodec/mpegaudiodec.c
+++ b/libavcodec/mpegaudiodec.c
@@ -1950,7 +1950,7 @@ static int decode_init_mp3on4(AVCodecContext * avctx)
         return -1;
     }
 
-    avpriv_mpeg4audio_get_config(&cfg, avctx->extradata, 
avctx->extradata_size);
+    avpriv_mpeg4audio_get_config(&cfg, avctx->extradata, 
avctx->extradata_size, 1);
     if (!cfg.chan_config || cfg.chan_config > 7) {
         av_log(avctx, AV_LOG_ERROR, "Invalid channel config number.\n");
         return -1;
diff --git a/libavformat/adtsenc.c b/libavformat/adtsenc.c
index ce002fe..094bb7e 100644
--- a/libavformat/adtsenc.c
+++ b/libavformat/adtsenc.c
@@ -35,7 +35,7 @@ int ff_adts_decode_extradata(AVFormatContext *s, ADTSContext 
*adts, uint8_t *buf
     int off;
 
     init_get_bits(&gb, buf, size * 8);
-    off = avpriv_mpeg4audio_get_config(&m4ac, buf, size);
+    off = avpriv_mpeg4audio_get_config(&m4ac, buf, size, 1);
     if (off < 0)
         return off;
     skip_bits_long(&gb, off);
diff --git a/libavformat/flvdec.c b/libavformat/flvdec.c
index 1459850..c2b4424 100644
--- a/libavformat/flvdec.c
+++ b/libavformat/flvdec.c
@@ -533,7 +533,7 @@ static int flv_read_packet(AVFormatContext *s, AVPacket 
*pkt)
             if (st->codec->codec_id == CODEC_ID_AAC) {
                 MPEG4AudioConfig cfg;
                 avpriv_mpeg4audio_get_config(&cfg, st->codec->extradata,
-                                         st->codec->extradata_size);
+                                             st->codec->extradata_size, 1);
                 st->codec->channels = cfg.channels;
                 if (cfg.ext_sample_rate)
                     st->codec->sample_rate = cfg.ext_sample_rate;
diff --git a/libavformat/isom.c b/libavformat/isom.c
index c5b01f2..aa9c523 100644
--- a/libavformat/isom.c
+++ b/libavformat/isom.c
@@ -434,7 +434,7 @@ int ff_mp4_read_dec_config_descr(AVFormatContext *fc, 
AVStream *st, AVIOContext
         if (st->codec->codec_id == CODEC_ID_AAC) {
             MPEG4AudioConfig cfg;
             avpriv_mpeg4audio_get_config(&cfg, st->codec->extradata,
-                                     st->codec->extradata_size);
+                                         st->codec->extradata_size, 1);
             st->codec->channels = cfg.channels;
             if (cfg.object_type == 29 && cfg.sampling_index < 3) // old mp3on4
                 st->codec->sample_rate = 
avpriv_mpa_freq_tab[cfg.sampling_index];
diff --git a/libavformat/latmenc.c b/libavformat/latmenc.c
index 679f2cc..775b108 100644
--- a/libavformat/latmenc.c
+++ b/libavformat/latmenc.c
@@ -54,7 +54,7 @@ static int latm_decode_extradata(LATMContext *ctx, uint8_t 
*buf, int size)
     MPEG4AudioConfig m4ac;
 
     init_get_bits(&gb, buf, size * 8);
-    ctx->off = avpriv_mpeg4audio_get_config(&m4ac, buf, size);
+    ctx->off = avpriv_mpeg4audio_get_config(&m4ac, buf, size, 1);
     if (ctx->off < 0)
         return ctx->off;
     skip_bits_long(&gb, ctx->off);
diff --git a/libavformat/matroskaenc.c b/libavformat/matroskaenc.c
index 1adb479..283ebfb 100644
--- a/libavformat/matroskaenc.c
+++ b/libavformat/matroskaenc.c
@@ -443,7 +443,7 @@ static void get_aac_sample_rates(AVFormatContext *s, 
AVCodecContext *codec, int
 {
     MPEG4AudioConfig mp4ac;
 
-    if (avpriv_mpeg4audio_get_config(&mp4ac, codec->extradata, 
codec->extradata_size) < 0) {
+    if (avpriv_mpeg4audio_get_config(&mp4ac, codec->extradata, 
codec->extradata_size, 1) < 0) {
         av_log(s, AV_LOG_WARNING, "Error parsing AAC extradata, unable to 
determine samplerate.\n");
         return;
     }
-- 
1.7.7

_______________________________________________
libav-devel mailing list
[email protected]
https://lists.libav.org/mailman/listinfo/libav-devel

Reply via email to