From 7b9bcd993c10144f65b62364ab1fd11be51bde9b Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Martin=20Storsj=C3=B6?= Date: Tue, 3 Sep 2013 13:53:23 +0300 Subject: [PATCH] 4xm: Check that the read track value is non-negative MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Reported-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind CC: libav-stable@libav.org Signed-off-by: Martin Storsjö (cherry picked from commit d719981273bc779c7d1e879d88404fd867f93a0e) Signed-off-by: Luca Barbato Conflicts: libavformat/4xm.c --- libavformat/4xm.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/libavformat/4xm.c b/libavformat/4xm.c index 5fb1921dd9..9dfb95650f 100644 --- a/libavformat/4xm.c +++ b/libavformat/4xm.c @@ -136,6 +136,8 @@ static int parse_strk(AVFormatContext *s, av_log(s, AV_LOG_ERROR, "current_track too large\n"); return AVERROR_INVALIDDATA; } + if (track < 0) + return AVERROR_INVALIDDATA; if (track + 1 > fourxm->track_count) { AudioTrack *tmp = av_realloc(fourxm->tracks, (track + 1) * sizeof(AudioTrack));