[FFmpeg-devel] [PATCH 2/3] avformat/mov: Fix parsing of saio/siaz atoms in encrypted content.

Carl Eugen Hoyos ceffmpeg at gmail.com
Fri Jan 5 22:41:09 EET 2018


2018-01-05 20:49 GMT+01:00 Jacob Trimble <modmaker-at-google.com at ffmpeg.org>:

> +    entry_count = avio_rb32(pb);
> +    encryption_index->auxiliary_offsets = av_malloc_array(sizeof(size_t), entry_count);

(sizeof(variable) instead of sizeof(type), please.)

But since this could be used for a dos attack, please change this
to something similar to 1112ba01.
If it is easy to avoid it, very short files should not allocate
gigabytes.

Carl Eugen


More information about the ffmpeg-devel mailing list