From 3776a72962b0622af17c4aef89a831da2cbaceca Mon Sep 17 00:00:00 2001 From: Andreas Cadhalpun Date: Wed, 6 Jan 2016 19:03:17 +0100 Subject: [PATCH] asfdec_o: make sure packet_size is non-zero before seeking MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This fixes infinite loops due to seeking back. Reviewed-by: Alexandra Hájková Signed-off-by: Andreas Cadhalpun --- libavformat/asfdec_o.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/libavformat/asfdec_o.c b/libavformat/asfdec_o.c index b81519fb18..4a3c81501e 100644 --- a/libavformat/asfdec_o.c +++ b/libavformat/asfdec_o.c @@ -1287,6 +1287,10 @@ static int asf_read_payload(AVFormatContext *s, AVPacket *pkt) } if (!asf_pkt) { if (asf->packet_offset + asf->packet_size <= asf->data_offset + asf->data_size) { + if (!asf->packet_size) { + av_log(s, AV_LOG_ERROR, "Invalid packet size 0.\n"); + return AVERROR_INVALIDDATA; + } avio_seek(pb, asf->packet_offset + asf->packet_size, SEEK_SET); av_log(s, AV_LOG_WARNING, "Skipping the stream with the invalid stream index %d.\n", asf->stream_index);