From a943a132f36f4df8fe2f749744677b71984abce7 Mon Sep 17 00:00:00 2001 From: Luca Barbato Date: Sat, 27 Apr 2013 18:20:47 +0200 Subject: [PATCH] aac: check the maximum number of channels Broken bitstreams could report a larger than specified number of channels and cause outbound writes. CC:libav-stable@libav.org --- libavcodec/aacdec.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/libavcodec/aacdec.c b/libavcodec/aacdec.c index 102c3d5d11..3219ec6185 100644 --- a/libavcodec/aacdec.c +++ b/libavcodec/aacdec.c @@ -141,6 +141,8 @@ static av_cold int che_configure(AACContext *ac, enum ChannelPosition che_pos, int type, int id, int *channels) { + if (*channels >= MAX_CHANNELS) + return AVERROR_INVALIDDATA; if (che_pos) { if (!ac->che[type][id]) { if (!(ac->che[type][id] = av_mallocz(sizeof(ChannelElement))))