summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJanne Grunau <janne-ffmpeg@jannau.net>2011-02-09 23:23:22 +0100
committerMichael Niedermayer <michaelni@gmx.at>2011-02-11 02:54:09 +0100
commit1a089285386decf7c41321f45e306c5d0c2ada82 (patch)
tree591876f62232e71ed48747f68fb7a9d0939de230
parent20708223dbd35b69a1b7cb542ee340c7c22af504 (diff)
downloadffmpeg-streaming-1a089285386decf7c41321f45e306c5d0c2ada82.zip
ffmpeg-streaming-1a089285386decf7c41321f45e306c5d0c2ada82.tar.gz
dvbsubdec: check against buffer overreads
Signed-off-by: Janne Grunau <janne-ffmpeg@jannau.net> (cherry picked from commit 493aa30adf88baf5bc734072592a22db586f0cfb)
-rw-r--r--libavcodec/dvbsubdec.c11
1 files changed, 9 insertions, 2 deletions
diff --git a/libavcodec/dvbsubdec.c b/libavcodec/dvbsubdec.c
index 401144f..4573713 100644
--- a/libavcodec/dvbsubdec.c
+++ b/libavcodec/dvbsubdec.c
@@ -1423,13 +1423,15 @@ static int dvbsub_decode(AVCodecContext *avctx,
#endif
- if (buf_size <= 2 || *buf != 0x0f)
+ if (buf_size <= 6 || *buf != 0x0f) {
+ av_dlog(avctx, "incomplete or broken packet");
return -1;
+ }
p = buf;
p_end = buf + buf_size;
- while (p < p_end && *p == 0x0f) {
+ while (p_end - p >= 6 && *p == 0x0f) {
p += 1;
segment_type = *p++;
page_id = AV_RB16(p);
@@ -1437,6 +1439,11 @@ static int dvbsub_decode(AVCodecContext *avctx,
segment_length = AV_RB16(p);
p += 2;
+ if (p_end - p < segment_length) {
+ av_dlog(avctx, "incomplete or broken packet");
+ return -1;
+ }
+
if (page_id == ctx->composition_id || page_id == ctx->ancillary_id ||
ctx->composition_id == -1 || ctx->ancillary_id == -1) {
switch (segment_type) {
OpenPOWER on IntegriCloud