On 03/29/2012 03:44 PM, Ronald S. Bultje wrote:

> From: "Ronald S. Bultje" <[email protected]>
> 
> This prevents sample_rate/data_length from going negative, which
> caused various crashes and undefined behaviour further down.
> 
> Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
> CC: [email protected]
> ---
>  libavcodec/tta.c |    8 +++++---
>  1 file changed, 5 insertions(+), 3 deletions(-)
> 
> diff --git a/libavcodec/tta.c b/libavcodec/tta.c
> index ad80246..808de04 100644
> --- a/libavcodec/tta.c
> +++ b/libavcodec/tta.c
> @@ -61,7 +61,8 @@ typedef struct TTAContext {
>      GetBitContext gb;
>      const AVCRC *crc_table;
>  
> -    int format, channels, bps, data_length;
> +    int format, channels, bps;
> +    unsigned data_length;
>      int frame_length, last_frame_length, total_frames;
>  
>      int32_t *decode_buffer;
> @@ -253,7 +254,7 @@ static av_cold int tta_decode_init(AVCodecContext * avctx)
>          }
>  
>          // prevent overflow
> -        if (avctx->sample_rate > 0x7FFFFF) {
> +        if (avctx->sample_rate > 0x7FFFFFu) {


this change doesn't make sense to me

>              av_log(avctx, AV_LOG_ERROR, "sample_rate too large\n");
>              return AVERROR(EINVAL);
>          }
> @@ -270,7 +271,8 @@ static av_cold int tta_decode_init(AVCodecContext * avctx)
>              s->data_length, s->frame_length, s->last_frame_length, 
> s->total_frames);
>  
>          // FIXME: seek table
> -        if (get_bits_left(&s->gb) < 32 * s->total_frames + 32)
> +        if (avctx->extradata_size <= 26 || s->total_frames > INT_MAX / 4 ||
> +            avctx->extradata_size - 26 < s->total_frames * 4)


this part looks ok.

-Justin
_______________________________________________
libav-devel mailing list
[email protected]
https://lists.libav.org/mailman/listinfo/libav-devel

Reply via email to