aac: check the maximum number of channels
authorReinhard Tartler <siretart@tauware.de>
Tue, 7 May 2013 05:13:50 +0000 (07:13 +0200)
committerReinhard Tartler <siretart@tauware.de>
Tue, 7 May 2013 05:13:50 +0000 (07:13 +0200)
Broken bitstreams could report a larger than specified number of
channels and cause outbound writes.

CC:libav-stable@libav.org
(cherry picked from commit a943a132f36f4df8fe2f749744677b71984abce7)

Signed-off-by: Luca Barbato <lu_zero@gentoo.org>
Conflicts:
libavcodec/aacdec.c

libavcodec/aacdec.c

index 6478c77..24e6ca6 100644 (file)
@@ -192,6 +192,8 @@ static av_cold int che_configure(AACContext *ac,
                                  enum ChannelPosition che_pos[4][MAX_ELEM_ID],
                                  int type, int id, int *channels)
 {
+    if (*channels >= MAX_CHANNELS)
+        return AVERROR_INVALIDDATA;
     if (che_pos[type][id]) {
         if (!ac->che[type][id]) {
             if (!(ac->che[type][id] = av_mallocz(sizeof(ChannelElement))))