Fix memory (re)allocation in matroskadec.c, related to MSVR-11-0080.
Whitespace of the patch cleaned up by Aurel Some of the issues have been reported by Steve Manzuik / Microsoft Vulnerability Research (MSVR) Signed-off-by: Michael Niedermayer <michaelni@gmx.at> (cherry picked from commit 956c901c68eff78288f40e3c8f41ee2fa081d4a8) Further suggestions from Kostya <kostya.shishkov@gmail.com> have been implemented by Reinhard Tartler <siretart@tauware.de> Signed-off-by: Reinhard Tartler <siretart@tauware.de> (cherry picked from commit 77d2ef13a8fa630e5081f14bde3fd20f84c90aec) NB: MSVR-11-0080 doesn't seem to exist. This issue seems to be known as MSVR11-011 instead. Fixes: CVE-2011-3504 Signed-off-by: Reinhard Tartler <siretart@tauware.de>
This commit is contained in:
parent
7a6bba627d
commit
222d18ab20
@ -759,11 +759,15 @@ static int ebml_parse_elem(MatroskaDemuxContext *matroska,
|
|||||||
uint32_t id = syntax->id;
|
uint32_t id = syntax->id;
|
||||||
uint64_t length;
|
uint64_t length;
|
||||||
int res;
|
int res;
|
||||||
|
void *newelem;
|
||||||
|
|
||||||
data = (char *)data + syntax->data_offset;
|
data = (char *)data + syntax->data_offset;
|
||||||
if (syntax->list_elem_size) {
|
if (syntax->list_elem_size) {
|
||||||
EbmlList *list = data;
|
EbmlList *list = data;
|
||||||
list->elem = av_realloc(list->elem, (list->nb_elem+1)*syntax->list_elem_size);
|
newelem = av_realloc(list->elem, (list->nb_elem+1)*syntax->list_elem_size);
|
||||||
|
if (!newelem)
|
||||||
|
return AVERROR(ENOMEM);
|
||||||
|
list->elem = newelem;
|
||||||
data = (char*)list->elem + list->nb_elem*syntax->list_elem_size;
|
data = (char*)list->elem + list->nb_elem*syntax->list_elem_size;
|
||||||
memset(data, 0, syntax->list_elem_size);
|
memset(data, 0, syntax->list_elem_size);
|
||||||
list->nb_elem++;
|
list->nb_elem++;
|
||||||
@ -883,6 +887,7 @@ static int matroska_decode_buffer(uint8_t** buf, int* buf_size,
|
|||||||
uint8_t* data = *buf;
|
uint8_t* data = *buf;
|
||||||
int isize = *buf_size;
|
int isize = *buf_size;
|
||||||
uint8_t* pkt_data = NULL;
|
uint8_t* pkt_data = NULL;
|
||||||
|
uint8_t* newpktdata;
|
||||||
int pkt_size = isize;
|
int pkt_size = isize;
|
||||||
int result = 0;
|
int result = 0;
|
||||||
int olen;
|
int olen;
|
||||||
@ -909,7 +914,12 @@ static int matroska_decode_buffer(uint8_t** buf, int* buf_size,
|
|||||||
zstream.avail_in = isize;
|
zstream.avail_in = isize;
|
||||||
do {
|
do {
|
||||||
pkt_size *= 3;
|
pkt_size *= 3;
|
||||||
pkt_data = av_realloc(pkt_data, pkt_size);
|
newpktdata = av_realloc(pkt_data, pkt_size);
|
||||||
|
if (!newpktdata) {
|
||||||
|
inflateEnd(&zstream);
|
||||||
|
goto failed;
|
||||||
|
}
|
||||||
|
pkt_data = newpktdata;
|
||||||
zstream.avail_out = pkt_size - zstream.total_out;
|
zstream.avail_out = pkt_size - zstream.total_out;
|
||||||
zstream.next_out = pkt_data + zstream.total_out;
|
zstream.next_out = pkt_data + zstream.total_out;
|
||||||
result = inflate(&zstream, Z_NO_FLUSH);
|
result = inflate(&zstream, Z_NO_FLUSH);
|
||||||
@ -930,7 +940,12 @@ static int matroska_decode_buffer(uint8_t** buf, int* buf_size,
|
|||||||
bzstream.avail_in = isize;
|
bzstream.avail_in = isize;
|
||||||
do {
|
do {
|
||||||
pkt_size *= 3;
|
pkt_size *= 3;
|
||||||
pkt_data = av_realloc(pkt_data, pkt_size);
|
newpktdata = av_realloc(pkt_data, pkt_size);
|
||||||
|
if (!newpktdata) {
|
||||||
|
BZ2_bzDecompressEnd(&bzstream);
|
||||||
|
goto failed;
|
||||||
|
}
|
||||||
|
pkt_data = newpktdata;
|
||||||
bzstream.avail_out = pkt_size - bzstream.total_out_lo32;
|
bzstream.avail_out = pkt_size - bzstream.total_out_lo32;
|
||||||
bzstream.next_out = pkt_data + bzstream.total_out_lo32;
|
bzstream.next_out = pkt_data + bzstream.total_out_lo32;
|
||||||
result = BZ2_bzDecompress(&bzstream);
|
result = BZ2_bzDecompress(&bzstream);
|
||||||
@ -985,13 +1000,17 @@ static void matroska_fix_ass_packet(MatroskaDemuxContext *matroska,
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static void matroska_merge_packets(AVPacket *out, AVPacket *in)
|
static int matroska_merge_packets(AVPacket *out, AVPacket *in)
|
||||||
{
|
{
|
||||||
out->data = av_realloc(out->data, out->size+in->size);
|
void *newdata = av_realloc(out->data, out->size+in->size);
|
||||||
|
if (!newdata)
|
||||||
|
return AVERROR(ENOMEM);
|
||||||
|
out->data = newdata;
|
||||||
memcpy(out->data+out->size, in->data, in->size);
|
memcpy(out->data+out->size, in->data, in->size);
|
||||||
out->size += in->size;
|
out->size += in->size;
|
||||||
av_destruct_packet(in);
|
av_destruct_packet(in);
|
||||||
av_free(in);
|
av_free(in);
|
||||||
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
static void matroska_convert_tag(AVFormatContext *s, EbmlList *list,
|
static void matroska_convert_tag(AVFormatContext *s, EbmlList *list,
|
||||||
@ -1494,11 +1513,13 @@ static int matroska_deliver_packet(MatroskaDemuxContext *matroska,
|
|||||||
memcpy(pkt, matroska->packets[0], sizeof(AVPacket));
|
memcpy(pkt, matroska->packets[0], sizeof(AVPacket));
|
||||||
av_free(matroska->packets[0]);
|
av_free(matroska->packets[0]);
|
||||||
if (matroska->num_packets > 1) {
|
if (matroska->num_packets > 1) {
|
||||||
|
void *newpackets;
|
||||||
memmove(&matroska->packets[0], &matroska->packets[1],
|
memmove(&matroska->packets[0], &matroska->packets[1],
|
||||||
(matroska->num_packets - 1) * sizeof(AVPacket *));
|
(matroska->num_packets - 1) * sizeof(AVPacket *));
|
||||||
matroska->packets =
|
newpackets = av_realloc(matroska->packets,
|
||||||
av_realloc(matroska->packets, (matroska->num_packets - 1) *
|
(matroska->num_packets - 1) * sizeof(AVPacket *));
|
||||||
sizeof(AVPacket *));
|
if (newpackets)
|
||||||
|
matroska->packets = newpackets;
|
||||||
} else {
|
} else {
|
||||||
av_freep(&matroska->packets);
|
av_freep(&matroska->packets);
|
||||||
}
|
}
|
||||||
|
Loading…
x
Reference in New Issue
Block a user