imc: check output buffer size before decoding
This commit is contained in:
parent
e9362aaedf
commit
86962b13f6
@ -651,7 +651,7 @@ static int imc_decode_frame(AVCodecContext * avctx,
|
|||||||
IMCContext *q = avctx->priv_data;
|
IMCContext *q = avctx->priv_data;
|
||||||
|
|
||||||
int stream_format_code;
|
int stream_format_code;
|
||||||
int imc_hdr, i, j;
|
int imc_hdr, i, j, out_size;
|
||||||
int flag;
|
int flag;
|
||||||
int bits, summer;
|
int bits, summer;
|
||||||
int counter, bitscount;
|
int counter, bitscount;
|
||||||
@ -662,6 +662,12 @@ static int imc_decode_frame(AVCodecContext * avctx,
|
|||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
out_size = COEFFS * av_get_bytes_per_sample(avctx->sample_fmt);
|
||||||
|
if (*data_size < out_size) {
|
||||||
|
av_log(avctx, AV_LOG_ERROR, "Output buffer is too small\n");
|
||||||
|
return AVERROR(EINVAL);
|
||||||
|
}
|
||||||
|
|
||||||
q->dsp.bswap16_buf(buf16, (const uint16_t*)buf, IMC_BLOCK_SIZE / 2);
|
q->dsp.bswap16_buf(buf16, (const uint16_t*)buf, IMC_BLOCK_SIZE / 2);
|
||||||
|
|
||||||
q->out_samples = data;
|
q->out_samples = data;
|
||||||
@ -808,7 +814,7 @@ static int imc_decode_frame(AVCodecContext * avctx,
|
|||||||
|
|
||||||
imc_imdct256(q);
|
imc_imdct256(q);
|
||||||
|
|
||||||
*data_size = COEFFS * sizeof(float);
|
*data_size = out_size;
|
||||||
|
|
||||||
return IMC_BLOCK_SIZE;
|
return IMC_BLOCK_SIZE;
|
||||||
}
|
}
|
||||||
|
Loading…
x
Reference in New Issue
Block a user