summaryrefslogtreecommitdiff
path: root/libavformat/smacker.c
diff options
context:
space:
mode:
authorMichael Niedermayer <michaelni@gmx.at>2006-05-13 11:37:56 +0000
committerMichael Niedermayer <michaelni@gmx.at>2006-05-13 11:37:56 +0000
commita443a2530d00b7019269202ac0f5ca8ba0a021c7 (patch)
tree9dfe3c9388c09a10ef32b64a871d3dac45495cb5 /libavformat/smacker.c
parent3a1a7e32ace7af47de74e8ae779cb4e04c89aa97 (diff)
sanity checks some might have been exploitable
Originally committed as revision 5370 to svn://svn.ffmpeg.org/ffmpeg/trunk
Diffstat (limited to 'libavformat/smacker.c')
-rw-r--r--libavformat/smacker.c7
1 files changed, 7 insertions, 0 deletions
diff --git a/libavformat/smacker.c b/libavformat/smacker.c
index 916dd84077..7733da3bd7 100644
--- a/libavformat/smacker.c
+++ b/libavformat/smacker.c
@@ -114,6 +114,13 @@ static int smacker_read_header(AVFormatContext *s, AVFormatParameters *ap)
for(i = 0; i < 7; i++)
smk->audio[i] = get_le32(pb);
smk->treesize = get_le32(pb);
+
+ if(smk->treesize >= UINT_MAX/4){ // smk->treesize + 16 must not overflow (this check is probably redundant)
+ av_log(s, AV_LOG_ERROR, "treesize too large\n");
+ return -1;
+ }
+
+//FIXME remove extradata "rebuilding"
smk->mmap_size = get_le32(pb);
smk->mclr_size = get_le32(pb);
smk->full_size = get_le32(pb);