angler-fishThe Vulnerability History Project

indeo4/5: check empty tile size in decode_mb_info().

      This prevents writing into a too small array if some parameters changed
without the tile being reallocated.

Based on a patch by Michael Niedermayer <michaelni@gmx.at>

Fixes CVE-2012-2800

CC:libav-stable@libav.org

Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
    
commit ae3da0ae5550053583a6f281ea7fd940497ea0d1
+3 -14
expand_less