]> rtime.felk.cvut.cz Git - frescor/ffmpeg.git/commitdiff
Fix remotely exploitable arbitrary code execution vulnerability.
authormichael <michael@9553f0bf-9b14-0410-a0b8-cfaf0461ba5b>
Wed, 28 Jan 2009 13:37:26 +0000 (13:37 +0000)
committermichael <michael@9553f0bf-9b14-0410-a0b8-cfaf0461ba5b>
Wed, 28 Jan 2009 13:37:26 +0000 (13:37 +0000)
Found by Tobias Klein / tk // trapkit / de /
See: http://www.trapkit.de/advisories/TKADV2009-004.txt

git-svn-id: file:///var/local/repositories/ffmpeg/trunk@16846 9553f0bf-9b14-0410-a0b8-cfaf0461ba5b

libavformat/4xm.c

index 513f51845abfe0979d899dc6dce3e6771fbb035c..74522f8d2704c6c15567b7fc4b69d603c416f296 100644 (file)
@@ -166,12 +166,13 @@ static int fourxm_read_header(AVFormatContext *s,
                 goto fail;
             }
             current_track = AV_RL32(&header[i + 8]);
+            if((unsigned)current_track >= UINT_MAX / sizeof(AudioTrack) - 1){
+                av_log(s, AV_LOG_ERROR, "current_track too large\n");
+                ret= -1;
+                goto fail;
+            }
             if (current_track + 1 > fourxm->track_count) {
                 fourxm->track_count = current_track + 1;
-                if((unsigned)fourxm->track_count >= UINT_MAX / sizeof(AudioTrack)){
-                    ret= -1;
-                    goto fail;
-                }
                 fourxm->tracks = av_realloc(fourxm->tracks,
                     fourxm->track_count * sizeof(AudioTrack));
                 if (!fourxm->tracks) {