From 1c31b26bdf66879a46a7a3e340da815c1b2125a8 Mon Sep 17 00:00:00 2001 From: Kostya Shishkov Date: Tue, 15 Mar 2011 20:37:37 +0100 Subject: [PATCH] Do not attempt to decode APE file with no frames. This fixes invalid reads/writes with this sample: http://packetstorm.linuxsecurity.com/1103-exploits/vlc105-dos.txt --- libavformat/ape.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/libavformat/ape.c b/libavformat/ape.c index 2de47ef483..187c9865a4 100644 --- a/libavformat/ape.c +++ b/libavformat/ape.c @@ -242,6 +242,10 @@ static int ape_read_header(AVFormatContext * s, AVFormatParameters * ap) avio_seek(pb, ape->wavheaderlength, SEEK_CUR); } + if(!ape->totalframes){ + av_log(s, AV_LOG_ERROR, "No frames in the file!\n"); + return AVERROR(EINVAL); + } if(ape->totalframes > UINT_MAX / sizeof(APEFrame)){ av_log(s, AV_LOG_ERROR, "Too many frames: %d\n", ape->totalframes); return -1;