This is CVE-2014-8962.
Reported-by: Michele Spagnuolo,
Google Security Team <mikispag@google.com>
https://git.xiph.org/?p=flac.git;a=commit;h=
5b3033a2b355068c11fe637e14ac742d273f076e
Change-Id: Ic9d1d567bd31323a6a9fce92e4acb0d1b60ce14e
*
***********************************************************************/
-static FLAC__byte ID3V2_TAG_[3] = { 'I', 'D', '3' };
+static const FLAC__byte ID3V2_TAG_[3] = { 'I', 'D', '3' };
/***********************************************************************
*
id = 0;
continue;
}
+
+ if(id >= 3)
+ return false;
+
if(x == ID3V2_TAG_[id]) {
id++;
i = 0;