|
Line 0
Link Here
|
|
|
1 |
--- libmpdemux/demux_audio.c.orig 2007-10-08 03:49:33.000000000 +0800 |
| 2 |
+++ libmpdemux/demux_audio.c 2008-02-02 21:01:44.000000000 +0800 |
| 3 |
@@ -229,6 +229,8 @@ |
| 4 |
ptr += 4; |
| 5 |
|
| 6 |
comment = ptr; |
| 7 |
+ if (&comment[length] < comments || &comment[length] >= &comments[blk_len]) |
| 8 |
+ return; |
| 9 |
c = comment[length]; |
| 10 |
comment[length] = 0; |
| 11 |
|
| 12 |
--- libmpdemux/demux_mov.c.orig 2007-10-08 03:49:33.000000000 +0800 |
| 13 |
+++ libmpdemux/demux_mov.c 2008-02-02 21:01:48.000000000 +0800 |
| 14 |
@@ -173,11 +173,12 @@ |
| 15 |
i=trak->chunkmap_size; |
| 16 |
while(i>0){ |
| 17 |
--i; |
| 18 |
- for(j=trak->chunkmap[i].first;j<last;j++){ |
| 19 |
+ j=FFMAX(trak->chunkmap[i].first, 0); |
| 20 |
+ for(;j<last;j++){ |
| 21 |
trak->chunks[j].desc=trak->chunkmap[i].sdid; |
| 22 |
trak->chunks[j].size=trak->chunkmap[i].spc; |
| 23 |
} |
| 24 |
- last=trak->chunkmap[i].first; |
| 25 |
+ last=FFMIN(trak->chunkmap[i].first, trak->chunks_size); |
| 26 |
} |
| 27 |
|
| 28 |
#if 0 |
| 29 |
@@ -235,6 +236,8 @@ |
| 30 |
s=0; |
| 31 |
for(j=0;j<trak->durmap_size;j++){ |
| 32 |
for(i=0;i<trak->durmap[j].num;i++){ |
| 33 |
+ if (s >= trak->samples_size) |
| 34 |
+ break; |
| 35 |
trak->samples[s].pts=pts; |
| 36 |
++s; |
| 37 |
pts+=trak->durmap[j].dur; |
| 38 |
@@ -246,6 +249,8 @@ |
| 39 |
for(j=0;j<trak->chunks_size;j++){ |
| 40 |
off_t pos=trak->chunks[j].pos; |
| 41 |
for(i=0;i<trak->chunks[j].size;i++){ |
| 42 |
+ if (s >= trak->samples_size) |
| 43 |
+ break; |
| 44 |
trak->samples[s].pos=pos; |
| 45 |
mp_msg(MSGT_DEMUX, MSGL_DBG3, "Sample %5d: pts=%8d off=0x%08X size=%d\n",s, |
| 46 |
trak->samples[s].pts, |
| 47 |
@@ -1568,8 +1573,7 @@ |
| 48 |
if( udta_len>udta_size) |
| 49 |
udta_len=udta_size; |
| 50 |
{ |
| 51 |
- char dump[udta_len-4]; |
| 52 |
- stream_read(demuxer->stream, (char *)&dump, udta_len-4-4); |
| 53 |
+ stream_skip(demuxer->stream, udta_len-4-4); |
| 54 |
udta_size -= udta_len; |
| 55 |
} |
| 56 |
} |
| 57 |
--- stream/url.c.orig 2007-10-08 03:49:26.000000000 +0800 |
| 58 |
+++ stream/url.c 2008-02-02 21:00:22.000000000 +0800 |
| 59 |
@@ -328,6 +328,7 @@ |
| 60 |
} |
| 61 |
} |
| 62 |
|
| 63 |
+ tmp = NULL; |
| 64 |
while(i < len) { |
| 65 |
// look for the next char that must be kept |
| 66 |
for (j=i;j<len;j++) { |
| 67 |
--- stream/stream_cddb.c.orig 2007-10-08 03:49:26.000000000 +0800 |
| 68 |
+++ stream/stream_cddb.c 2008-02-02 21:02:51.000000000 +0800 |
| 69 |
@@ -53,6 +53,7 @@ |
| 70 |
#include "version.h" |
| 71 |
#include "stream.h" |
| 72 |
#include "network.h" |
| 73 |
+#include "libavutil/intreadwrite.h" |
| 74 |
|
| 75 |
#define DEFAULT_FREEDB_SERVER "freedb.freedb.org" |
| 76 |
#define DEFAULT_CACHE_DIR "/.cddb/" |
| 77 |
@@ -453,8 +454,9 @@ |
| 78 |
} else { |
| 79 |
len = ptr2-ptr+1; |
| 80 |
} |
| 81 |
+ len = FFMIN(sizeof(album_title) - 1, len); |
| 82 |
strncpy(album_title, ptr, len); |
| 83 |
- album_title[len-2]='\0'; |
| 84 |
+ album_title[len]='\0'; |
| 85 |
} |
| 86 |
mp_msg(MSGT_DEMUX, MSGL_STATUS, MSGTR_MPDEMUX_CDDB_ParseOKFoundAlbumTitle, album_title); |
| 87 |
return 0; |
| 88 |
@@ -490,8 +492,9 @@ |
| 89 |
} else { |
| 90 |
len = ptr2-ptr+1; |
| 91 |
} |
| 92 |
+ len = FFMIN(sizeof(album_title) - 1, len); |
| 93 |
strncpy(album_title, ptr, len); |
| 94 |
- album_title[len-2]='\0'; |
| 95 |
+ album_title[len]='\0'; |
| 96 |
} |
| 97 |
mp_msg(MSGT_DEMUX, MSGL_STATUS, MSGTR_MPDEMUX_CDDB_ParseOKFoundAlbumTitle, album_title); |
| 98 |
return cddb_request_titles(cddb_data); |