/* mimetype */
if (isv34) {
- taglen -= avio_get_str(pb, taglen, mimetype, sizeof(mimetype));
+ int ret = avio_get_str(pb, taglen, mimetype, sizeof(mimetype));
+ if (ret < 0 || ret >= taglen)
+ goto fail;
+ taglen -= ret;
} else {
if (avio_read(pb, mimetype, 3) < 0)
goto fail;
av_dict_set(&st->metadata, "comment", apic->type, 0);
- av_init_packet(&st->attached_pic);
+ av_packet_unref(&st->attached_pic);
st->attached_pic.buf = apic->buf;
st->attached_pic.data = apic->buf->data;
st->attached_pic.size = apic->buf->size - AV_INPUT_BUFFER_PADDING_SIZE;