1
From a3d471e500674c31fa4f52a62ef789d5e7fdbd3c Mon Sep 17 00:00:00 2001
2
From: Laurent Aimar <fenrir@videolan.org>
3
Date: Sun, 11 Sep 2011 23:26:12 +0200
4
Subject: [PATCH 62/70] oggdec: fix out of bound write in the ogg demuxer
6
Between ogg_save() and ogg_restore() calls, the number of streams
7
could have been reduced.
9
Signed-off-by: Luca Barbato <lu_zero@gentoo.org>
10
(cherry picked from commit 0e7efb9d23c3641d50caa288818e8c27647ce74d)
12
Signed-off-by: Anton Khirnov <anton@khirnov.net>
14
libavformat/oggdec.c | 14 ++++++++++++--
15
1 files changed, 12 insertions(+), 2 deletions(-)
17
diff --git a/libavformat/oggdec.c b/libavformat/oggdec.c
18
index 25f5cd8..1820167 100644
19
--- a/libavformat/oggdec.c
20
+++ b/libavformat/oggdec.c
21
@@ -92,14 +92,24 @@ static int ogg_restore(AVFormatContext *s, int discard)
22
ogg->state = ost->next;
25
+ struct ogg_stream *old_streams = ogg->streams;
27
for (i = 0; i < ogg->nstreams; i++)
28
av_free (ogg->streams[i].buf);
30
avio_seek (bc, ost->pos, SEEK_SET);
31
ogg->curidx = ost->curidx;
32
ogg->nstreams = ost->nstreams;
33
- memcpy(ogg->streams, ost->streams,
34
- ost->nstreams * sizeof(*ogg->streams));
35
+ ogg->streams = av_realloc (ogg->streams,
36
+ ogg->nstreams * sizeof (*ogg->streams));
39
+ memcpy(ogg->streams, ost->streams,
40
+ ost->nstreams * sizeof(*ogg->streams));
42
+ av_free(old_streams);