commit | ef84190a1ab777c35ea9fec64c3ab6ce641b79e5 | [log] [tgz] |
---|---|---|
author | Reinhard Tartler <siretart@tauware.de> | Tue Feb 09 18:51:11 2010 +0000 |
committer | Reinhard Tartler <siretart@tauware.de> | Tue Feb 09 18:51:11 2010 +0000 |
tree | 966da386d4c234ab1b4cc9f0be10d4331684a46a | |
parent | 7db16a81733e9380eaf85dd8db0e4080841243e4 [diff] |
Fix possible buffer over-read in vorbis_comment, fix it double to be sure. First, make s signed, so that comparisons against end - p will not be made as unsigned, making the check incorrectly pass if p is beyond end. Also ensure that p will never be > end, so the code is correct also if buf is not padded. backported r20014 by reimar Originally committed as revision 21711 to svn://svn.ffmpeg.org/ffmpeg/branches/0.5