summaryrefslogtreecommitdiffstats
path: root/libmpdemux
diff options
context:
space:
mode:
authoreugeni <eugeni@b3059339-0415-0410-9bf9-f77b7e298cf2>2008-05-02 13:33:14 +0000
committereugeni <eugeni@b3059339-0415-0410-9bf9-f77b7e298cf2>2008-05-02 13:33:14 +0000
commit547cc5772c61a58c9fb5f9800bd9bc1e550218d1 (patch)
treefe524f9462ad3a1302a37fc777eaa1121b67afa5 /libmpdemux
parentefd42817e434c17a8bc0035ef4586ffe3f59ffa2 (diff)
downloadmpv-547cc5772c61a58c9fb5f9800bd9bc1e550218d1.tar.bz2
mpv-547cc5772c61a58c9fb5f9800bd9bc1e550218d1.tar.xz
Check ASF packet size before calling demux_asf_read_packet. Fixes segfault
with damaged ASF files. git-svn-id: svn://svn.mplayerhq.hu/mplayer/trunk@26644 b3059339-0415-0410-9bf9-f77b7e298cf2
Diffstat (limited to 'libmpdemux')
-rw-r--r--libmpdemux/demux_asf.c6
1 files changed, 5 insertions, 1 deletions
diff --git a/libmpdemux/demux_asf.c b/libmpdemux/demux_asf.c
index 40614f3745..7d5a164886 100644
--- a/libmpdemux/demux_asf.c
+++ b/libmpdemux/demux_asf.c
@@ -3,6 +3,7 @@
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
+#include <assert.h>
#include "config.h"
#include "mp_msg.h"
@@ -501,6 +502,7 @@ static int demux_asf_fill_buffer(demuxer_t *demux, demux_stream_t *ds){
p++;
//printf(" group part: %d bytes\n",len2);
if(len2 > len - 1) break; // Not enough data
+ assert(len2 > 0 && len2 <= asf->packetsize);
demux_asf_read_packet(demux,p,len2,streamno,seq,x,duration,-1,keyframe);
p+=len2;
len-=len2+1;
@@ -513,8 +515,10 @@ static int demux_asf_fill_buffer(demuxer_t *demux, demux_stream_t *ds){
default:
// NO GROUPING:
//printf("fragment offset: %d \n",sh->x);
- if (!asf->asf_is_dvr_ms || asf->found_first_key_frame)
+ if (!asf->asf_is_dvr_ms || asf->found_first_key_frame) {
+ assert(len > 0 && len <= asf->packetsize);
demux_asf_read_packet(demux,p,len,streamno,seq,time2,duration,x,keyframe);
+ }
p+=len;
break;
}