]> git.sesse.net Git - ffmpeg/commitdiff
rtmp: Prevent reading outside of an allocate buffer when receiving server bandwidth...
authorSamuel Pitoiset <samuel.pitoiset@gmail.com>
Thu, 26 Jul 2012 12:05:18 +0000 (14:05 +0200)
committerMartin Storsjö <martin@martin.st>
Thu, 26 Jul 2012 19:56:54 +0000 (22:56 +0300)
Signed-off-by: Martin Storsjö <martin@martin.st>
libavformat/rtmpproto.c

index a2efe3882fe495b1ce915fa3bde21a1402ba0711..183afae4e8d2714ff7df59a4d02016a68ef5761f 100644 (file)
@@ -950,6 +950,13 @@ static int handle_server_bw(URLContext *s, RTMPPacket *pkt)
 {
     RTMPContext *rt = s->priv_data;
 
+    if (pkt->data_size < 4) {
+        av_log(s, AV_LOG_ERROR,
+               "Too short server bandwidth report packet (%d)\n",
+               pkt->data_size);
+        return AVERROR_INVALIDDATA;
+    }
+
     rt->server_bw = AV_RB32(pkt->data);
     if (rt->server_bw <= 0) {
         av_log(s, AV_LOG_ERROR, "Incorrect server bandwidth %d\n",