[libav-commits] adxenc: check output buffer size before writing

Justin Ruggles git at libav.org
Wed Jan 4 00:53:19 CET 2012


Module: libav
Branch: master
Commit: 754ebd1a5b68dd63ccceb50a8a852fe8d0c94354

Author:    Justin Ruggles <justin.ruggles at gmail.com>
Committer: Justin Ruggles <justin.ruggles at gmail.com>
Date:      Mon Dec 19 10:56:18 2011 -0500

adxenc: check output buffer size before writing

---

 libavcodec/adxenc.c |   16 ++++++++++++++--
 1 files changed, 14 insertions(+), 2 deletions(-)

diff --git a/libavcodec/adxenc.c b/libavcodec/adxenc.c
index 2664353..20f2798 100644
--- a/libavcodec/adxenc.c
+++ b/libavcodec/adxenc.c
@@ -87,6 +87,9 @@ static int adx_encode_header(AVCodecContext *avctx, uint8_t *buf, int bufsize)
 {
     ADXContext *c = avctx->priv_data;
 
+    if (bufsize < HEADER_SIZE)
+        return AVERROR(EINVAL);
+
     bytestream_put_be16(&buf, 0x8000);              /* header signature */
     bytestream_put_be16(&buf, HEADER_SIZE - 4);     /* copyright offset */
     bytestream_put_byte(&buf, 3);                   /* encoding */
@@ -140,10 +143,19 @@ static int adx_encode_frame(AVCodecContext *avctx, uint8_t *frame,
     int ch;
 
     if (!c->header_parsed) {
-        int hdrsize = adx_encode_header(avctx, dst, buf_size);
-        dst += hdrsize;
+        int hdrsize;
+        if ((hdrsize = adx_encode_header(avctx, dst, buf_size)) < 0) {
+            av_log(avctx, AV_LOG_ERROR, "output buffer is too small\n");
+            return AVERROR(EINVAL);
+        }
+        dst      += hdrsize;
+        buf_size -= hdrsize;
         c->header_parsed = 1;
     }
+    if (buf_size < BLOCK_SIZE * avctx->channels) {
+        av_log(avctx, AV_LOG_ERROR, "output buffer is too small\n");
+        return AVERROR(EINVAL);
+    }
 
     for (ch = 0; ch < avctx->channels; ch++) {
         adx_encode(c, dst, samples + ch, &c->prev[ch], avctx->channels);



More information about the libav-commits mailing list