[FFmpeg-devel] [PATCH 2/3] avformat/mov: Fix parsing of saio/siaz atoms in encrypted content.
    Carl Eugen Hoyos 
    ceffmpeg at gmail.com
       
    Fri Jan  5 22:41:09 EET 2018
    
    
  
2018-01-05 20:49 GMT+01:00 Jacob Trimble <modmaker-at-google.com at ffmpeg.org>:
> +    entry_count = avio_rb32(pb);
> +    encryption_index->auxiliary_offsets = av_malloc_array(sizeof(size_t), entry_count);
(sizeof(variable) instead of sizeof(type), please.)
But since this could be used for a dos attack, please change this
to something similar to 1112ba01.
If it is easy to avoid it, very short files should not allocate
gigabytes.
Carl Eugen
    
    
More information about the ffmpeg-devel
mailing list