[FFmpeg-devel] [PATCH 2/4] avformat/mxfdec: Check count in mxf_read_strong_ref_array()
Michael Niedermayer
michael at niedermayer.cc
Sun Mar 13 01:52:25 EET 2022
Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
---
libavformat/mxfdec.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
diff --git a/libavformat/mxfdec.c b/libavformat/mxfdec.c
index b85c10bf19..d7cdd22c8a 100644
--- a/libavformat/mxfdec.c
+++ b/libavformat/mxfdec.c
@@ -932,7 +932,13 @@ static int mxf_read_cryptographic_context(void *arg, AVIOContext *pb, int tag, i
static int mxf_read_strong_ref_array(AVIOContext *pb, UID **refs, int *count)
{
- *count = avio_rb32(pb);
+ unsigned c = avio_rb32(pb);
+
+ //avio_read() used int
+ if (c > INT_MAX / sizeof(UID))
+ return AVERROR_PATCHWELCOME;
+ *count = c;
+
av_free(*refs);
*refs = av_calloc(*count, sizeof(UID));
if (!*refs) {
--
2.17.1
More information about the ffmpeg-devel
mailing list