mov: validate number of DataReferenceBox entries against box size
authorJanne Grunau <janne-libav@jannau.net>
Mon, 26 Nov 2012 21:18:31 +0000 (22:18 +0100)
committerJanne Grunau <janne-libav@jannau.net>
Fri, 7 Dec 2012 10:43:28 +0000 (11:43 +0100)
commit8cc2fa1e5db0655c053b35c948ef05ba0fe13707
tree0d941674dc103cf342a49ec58185a95d51237a4d
parent80b6b31417c6791f9d4f1bc8c3c2a726d71e45e0
mov: validate number of DataReferenceBox entries against box size

Avoids a 2G memory allocation and parsing of random data in
mov_read_dref(). The fuzzed sample sample.mp4_s224424 triggers this.
libavformat/mov.c