# HG changeset patch # User gpoirier # Date 1177888719 0 # Node ID 7eba8b456a3f35fc6682a4445c30d4ebe1f85dc3 # Parent 4f351b1e02bc81929eb4e792caaedaa1e84a8763 prevent going out of the buffer if the nal size does not fit in the buffer. Patch by Mean % fixounet A free P fr % Original thread: Date: Apr 29, 2007 2:00 PM Subject: Re: [Ffmpeg-devel] [patch] h264.c, dont go beyond buffer in h264_decode_nal_unit diff -r 4f351b1e02bc -r 7eba8b456a3f h264.c --- a/h264.c Sun Apr 29 13:25:32 2007 +0000 +++ b/h264.c Sun Apr 29 23:18:39 2007 +0000 @@ -8122,7 +8122,7 @@ nalsize = 0; for(i = 0; i < h->nal_length_size; i++) nalsize = (nalsize << 8) | buf[buf_index++]; - if(nalsize <= 1 || nalsize > buf_size){ + if(nalsize <= 1 || (nalsize+buf_index > buf_size)){ if(nalsize == 1){ buf_index++; continue;