mirror of
https://gitee.com/openharmony/third_party_ffmpeg
synced 2024-11-27 05:00:37 +00:00
ogg: fix double free when finding length of small chained oggs.
ogg_save() copies streams[], but doesn't keep track of free()'ed struct members. Thus, if in between a call to ogg_save() and ogg_restore(), streams[].private was free()'ed, this would result in a double free -> crash, which happened when e.g. playing small chained ogg fragments.
This commit is contained in:
parent
ef1ee362b3
commit
9ed6cbc3ee
@ -238,7 +238,8 @@ static int ogg_read_page(AVFormatContext *s, int *str)
|
||||
|
||||
for (n = 0; n < ogg->nstreams; n++) {
|
||||
av_freep(&ogg->streams[n].buf);
|
||||
av_freep(&ogg->streams[n].private);
|
||||
if (!ogg->state || ogg->state->streams[n].private != ogg->streams[n].private)
|
||||
av_freep(&ogg->streams[n].private);
|
||||
}
|
||||
ogg->curidx = -1;
|
||||
ogg->nstreams = 0;
|
||||
|
Loading…
Reference in New Issue
Block a user