From patchwork Sun Jan 26 05:10:27 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Andreas Rheinhardt X-Patchwork-Id: 17550 Return-Path: X-Original-To: patchwork@ffaux-bg.ffmpeg.org Delivered-To: patchwork@ffaux-bg.ffmpeg.org Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org [79.124.17.100]) by ffaux.localdomain (Postfix) with ESMTP id 31EF7449CE2 for ; Sun, 26 Jan 2020 07:10:47 +0200 (EET) Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 0E82468AEDB; Sun, 26 Jan 2020 07:10:47 +0200 (EET) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from mail-wm1-f67.google.com (mail-wm1-f67.google.com [209.85.128.67]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 34FA268AD3C for ; Sun, 26 Jan 2020 07:10:40 +0200 (EET) Received: by mail-wm1-f67.google.com with SMTP id t14so3556405wmi.5 for ; Sat, 25 Jan 2020 21:10:40 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=/LvOlb2vPP9lriZygRNd029s1lKfWxupkE5qm/JPUM4=; b=sgsEEP9sGi67vsyLQ8G8kz5kR2U+X2NPu/sQDhEA7FJSs3IS/gjrrfThceL7txGbWL vYGc7gmx+da45ulPKJMxlYW16mpfKh8OilO0x0MQTbccWAsiFA/X8gvcm7HS5vqOo8uH UZydEGp6z7qtZTrYD/AYyu5DKDw2yCrckDKy00Tni9y/NRya0ydN6JxOEfPPZXYTCTqr XUkAHVh1oG3LMZw24onNJ5wN6NUv3SfVhoFY5zpkLsszeguoSWcCY9a/XckR2wN7xgN/ uOEZIESGTqJM7ExVBkIgSwXkM86SS4ZDjrsuUGFnH1k4zNIhIfBHgn2idLMMhx0geHT+ 5NDg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=/LvOlb2vPP9lriZygRNd029s1lKfWxupkE5qm/JPUM4=; b=uQiKg/51FdfRBzwwgeTE8VMcTdpadWG2euSrr3nARpkRZwVzfsjw30yKnXmQ1v96sj jeNcOGpX2+bi6E5YzwkLIVIDNcDjrnChZT9rQKv8TGtU1w5yHDAcj4di+yJsnxNBzrrb dcd1l9j3oD2xjuFJgPeHC7NfPzlhF2S8Ey4kIK4+k4PL6Q+S247KAx1+O+n7V9LbI2+K hWfeiLsN1/js3l8XYKHLnoMishZQrrSkQYKVdG359yF5QVlTdGsZQsjnxbvWF7L/aPcg 7AKG8n6kj/ASAbdriGKEBZRa24sKzgQhP9lH0IwPpx77sS06wSaQIuFOvQUREhl+M3lz FmBQ== X-Gm-Message-State: APjAAAVgqqYaMQdvl3YT42iqoAQfvdpemqWMiy6FZgtuVODXXJM0HAoR fUCD2YSOF2dEdeuLTFWUBjNSMefe X-Google-Smtp-Source: APXvYqwDrXzZ27xZvrX0JWLc1e8rRT2UE6+X9U2/D3OeTqPEKryAObVw56/+anpcLT2VXKHCaAY1XA== X-Received: by 2002:a1c:7c05:: with SMTP id x5mr6776479wmc.15.1580015439086; Sat, 25 Jan 2020 21:10:39 -0800 (PST) Received: from sblaptop.fritz.box (ipbcc08bbf.dynamic.kabel-deutschland.de. [188.192.139.191]) by smtp.gmail.com with ESMTPSA id y139sm13486305wmd.24.2020.01.25.21.10.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 25 Jan 2020 21:10:38 -0800 (PST) From: Andreas Rheinhardt To: ffmpeg-devel@ffmpeg.org Date: Sun, 26 Jan 2020 06:10:27 +0100 Message-Id: <20200126051028.27455-1-andreas.rheinhardt@gmail.com> X-Mailer: git-send-email 2.20.1 In-Reply-To: <20200101005837.11356-1-andreas.rheinhardt@gmail.com> References: <20200101005837.11356-1-andreas.rheinhardt@gmail.com> MIME-Version: 1.0 Subject: [FFmpeg-devel] [PATCH 29/30] avformat/matroskaenc: Check BlockAdditional size before use X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Cc: Andreas Rheinhardt Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" Don't read a 64bit number before having checked that the data is at least 8 bytes long. Signed-off-by: Andreas Rheinhardt --- libavformat/matroskaenc.c | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/libavformat/matroskaenc.c b/libavformat/matroskaenc.c index 444032b431..8fc672a31f 100644 --- a/libavformat/matroskaenc.c +++ b/libavformat/matroskaenc.c @@ -2100,9 +2100,13 @@ static void mkv_write_block(AVFormatContext *s, AVIOContext *pb, AV_PKT_DATA_MATROSKA_BLOCKADDITIONAL, &side_data_size); if (side_data) { - additional_id = AV_RB64(side_data); - side_data += 8; - side_data_size -= 8; + if (side_data_size < 8) { + side_data_size = 0; + } else { + additional_id = AV_RB64(side_data); + side_data += 8; + side_data_size -= 8; + } } if ((side_data_size && additional_id == 1) || discard_padding) {