mirror of
https://git.ffmpeg.org/ffmpeg.git
synced 2024-12-11 17:55:21 +00:00
Do not attempt to decode APE file with no frames
This fixes invalid reads/writes with this sample: http://packetstorm.linuxsecurity.com/1103-exploits/vlc105-dos.txt
This commit is contained in:
parent
1dac4d5547
commit
8312e3fc90
@ -242,6 +242,10 @@ static int ape_read_header(AVFormatContext * s, AVFormatParameters * ap)
|
|||||||
avio_seek(pb, ape->wavheaderlength, SEEK_CUR);
|
avio_seek(pb, ape->wavheaderlength, SEEK_CUR);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if(!ape->totalframes){
|
||||||
|
av_log(s, AV_LOG_ERROR, "No frames in the file!\n");
|
||||||
|
return AVERROR(EINVAL);
|
||||||
|
}
|
||||||
if(ape->totalframes > UINT_MAX / sizeof(APEFrame)){
|
if(ape->totalframes > UINT_MAX / sizeof(APEFrame)){
|
||||||
av_log(s, AV_LOG_ERROR, "Too many frames: %d\n", ape->totalframes);
|
av_log(s, AV_LOG_ERROR, "Too many frames: %d\n", ape->totalframes);
|
||||||
return -1;
|
return -1;
|
||||||
|
Loading…
Reference in New Issue
Block a user