From: Reimar Döffinger Date: Sat, 15 Aug 2009 00:02:42 +0000 (+0000) Subject: Fix cmd_pos bounds check to avoid the overflow case. X-Git-Tag: v0.6~3576 X-Git-Url: http://git.osdn.net/view?a=commitdiff_plain;h=ffbe087b589506cb0e671fa711e5c2c6ea203ac0;p=coroid%2Flibav_saccubus.git Fix cmd_pos bounds check to avoid the overflow case. Originally committed as revision 19640 to svn://svn.ffmpeg.org/ffmpeg/trunk --- diff --git a/libavcodec/dvdsubdec.c b/libavcodec/dvdsubdec.c index a99b7af85..b445d3e45 100644 --- a/libavcodec/dvdsubdec.c +++ b/libavcodec/dvdsubdec.c @@ -191,7 +191,7 @@ static int decode_dvd_subtitles(AVSubtitle *sub_header, cmd_pos = READ_OFFSET(buf + cmd_pos); - while ((cmd_pos + 2 + offset_size) < buf_size) { + while (cmd_pos > 0 && cmd_pos < buf_size - 2 - offset_size) { date = AV_RB16(buf + cmd_pos); next_cmd_pos = READ_OFFSET(buf + cmd_pos + 2); dprintf(NULL, "cmd_pos=0x%04x next=0x%04x date=%d\n",