vorbis: make sure ch is non zero before calling vorbis_residue_decode
authorMichael Niedermayer <michaelni@gmx.at>
Wed, 4 Jan 2012 20:55:52 +0000 (21:55 +0100)
committerMichael Niedermayer <michaelni@gmx.at>
Wed, 4 Jan 2012 21:19:02 +0000 (22:19 +0100)
This possibly makes part of the CVE-2011-3895 fix unneeded.

Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
(cherry picked from commit ff7f198d7f9504f71676327be0be47661cfe39d6)

Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
libavcodec/vorbisdec.c

index c99401b..4bd1cf2 100644 (file)
@@ -1575,9 +1575,11 @@ static int vorbis_parse_audio_packet(vorbis_context *vc)
             av_log(vc->avccontext, AV_LOG_ERROR, "Too many channels in vorbis_floor_decode.\n");
             return -1;
         }
-        ret = vorbis_residue_decode(vc, residue, ch, do_not_decode, ch_res_ptr, vlen, ch_left);
-        if (ret < 0)
-            return ret;
+        if (ch) {
+            ret = vorbis_residue_decode(vc, residue, ch, do_not_decode, ch_res_ptr, vlen, ch_left);
+            if (ret < 0)
+                return ret;
+        }
 
         ch_res_ptr += ch * vlen;
         ch_left -= ch;