On 03/29/2012 03:44 PM, Ronald S. Bultje wrote: > From: "Ronald S. Bultje" <[email protected]> > > This prevents sample_rate/data_length from going negative, which > caused various crashes and undefined behaviour further down. > > Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind > CC: [email protected] > --- > libavcodec/tta.c | 8 +++++--- > 1 file changed, 5 insertions(+), 3 deletions(-) > > diff --git a/libavcodec/tta.c b/libavcodec/tta.c > index ad80246..808de04 100644 > --- a/libavcodec/tta.c > +++ b/libavcodec/tta.c > @@ -61,7 +61,8 @@ typedef struct TTAContext { > GetBitContext gb; > const AVCRC *crc_table; > > - int format, channels, bps, data_length; > + int format, channels, bps; > + unsigned data_length; > int frame_length, last_frame_length, total_frames; > > int32_t *decode_buffer; > @@ -253,7 +254,7 @@ static av_cold int tta_decode_init(AVCodecContext * avctx) > } > > // prevent overflow > - if (avctx->sample_rate > 0x7FFFFF) { > + if (avctx->sample_rate > 0x7FFFFFu) {
this change doesn't make sense to me > av_log(avctx, AV_LOG_ERROR, "sample_rate too large\n"); > return AVERROR(EINVAL); > } > @@ -270,7 +271,8 @@ static av_cold int tta_decode_init(AVCodecContext * avctx) > s->data_length, s->frame_length, s->last_frame_length, > s->total_frames); > > // FIXME: seek table > - if (get_bits_left(&s->gb) < 32 * s->total_frames + 32) > + if (avctx->extradata_size <= 26 || s->total_frames > INT_MAX / 4 || > + avctx->extradata_size - 26 < s->total_frames * 4) this part looks ok. -Justin _______________________________________________ libav-devel mailing list [email protected] https://lists.libav.org/mailman/listinfo/libav-devel
