[FFmpeg-devel] [PATCH 2/4] avformat/mxfdec: Check count in mxf_read_strong_ref_array()
Tomas Härdin
tjoppen at acc.umu.se
Mon Mar 14 21:19:51 EET 2022
sön 2022-03-13 klockan 00:52 +0100 skrev Michael Niedermayer:
> Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
> ---
> libavformat/mxfdec.c | 8 +++++++-
> 1 file changed, 7 insertions(+), 1 deletion(-)
>
> diff --git a/libavformat/mxfdec.c b/libavformat/mxfdec.c
> index b85c10bf19..d7cdd22c8a 100644
> --- a/libavformat/mxfdec.c
> +++ b/libavformat/mxfdec.c
> @@ -932,7 +932,13 @@ static int mxf_read_cryptographic_context(void
> *arg, AVIOContext *pb, int tag, i
>
> static int mxf_read_strong_ref_array(AVIOContext *pb, UID **refs,
> int *count)
> {
> - *count = avio_rb32(pb);
> + unsigned c = avio_rb32(pb);
not uint32_t?
> +
> + //avio_read() used int
> + if (c > INT_MAX / sizeof(UID))
> + return AVERROR_PATCHWELCOME;
> + *count = c;
> +
This should already be caught by av_calloc(), no?
/Tomas
More information about the ffmpeg-devel
mailing list