OSDN Git Service

lavf/mp3enc: make sure the header is valid before writing audio pkt.
authorClément Bœsch <clement.boesch@smartjog.com>
Fri, 16 Nov 2012 08:21:17 +0000 (10:21 +0200)
committerClément Bœsch <ubitux@gmail.com>
Fri, 16 Nov 2012 13:11:08 +0000 (14:11 +0100)
An invalid header can lead avpriv_mpegaudio_decode_header() to overread
and/or div by zero.

libavformat/mp3enc.c

index 044eb29..cc9f0d0 100644 (file)
@@ -262,8 +262,14 @@ static int mp3_write_audio_packet(AVFormatContext *s, AVPacket *pkt)
     if (pkt->data && pkt->size >= 4) {
         MPADecodeHeader c;
         int av_unused base;
+        uint32_t head = AV_RB32(pkt->data);
 
-        avpriv_mpegaudio_decode_header(&c, AV_RB32(pkt->data));
+        if (ff_mpa_check_header(head) < 0) {
+            av_log(s, AV_LOG_WARNING, "Audio packet of size %d (starting with %08X...) "
+                   "is invalid, writing it anyway.\n", pkt->size, head);
+            return ff_raw_write_packet(s, pkt);
+        }
+        avpriv_mpegaudio_decode_header(&c, head);
 
         if (!mp3->initial_bitrate)
             mp3->initial_bitrate = c.bit_rate;