From fc85646ad495f3418042468da415af73a7a07334 Mon Sep 17 00:00:00 2001 From: Andreas Cadhalpun Date: Thu, 24 Nov 2016 01:06:35 +0100 Subject: libopusdec: fix out-of-bounds read Signed-off-by: Andreas Cadhalpun --- libavcodec/libopusdec.c | 7 +++++++ 1 file changed, 7 insertions(+) (limited to 'libavcodec') diff --git a/libavcodec/libopusdec.c b/libavcodec/libopusdec.c index 75eaf9bd48..781635615c 100644 --- a/libavcodec/libopusdec.c +++ b/libavcodec/libopusdec.c @@ -48,6 +48,13 @@ static av_cold int libopus_decode_init(AVCodecContext *avc) avc->channels = 2; } + avc->channels = avc->extradata_size >= 10 ? avc->extradata[9] : (avc->channels == 1) ? 1 : 2; + if (avc->channels <= 0) { + av_log(avc, AV_LOG_WARNING, + "Invalid number of channels %d, defaulting to stereo\n", avc->channels); + avc->channels = 2; + } + avc->sample_rate = 48000; avc->sample_fmt = avc->request_sample_fmt == AV_SAMPLE_FMT_FLT ? AV_SAMPLE_FMT_FLT : AV_SAMPLE_FMT_S16; -- cgit v1.2.3