angler-fishThe Vulnerability History Project

atrac3: Fix crash in tonal component decoding.

      Add a check to avoid writing past the end of the channel_unit.components[]
array.

Bug Found by: cosminamironesei
Fixes CVE-2012-0853
CC: libav-stable@libav.org

Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
Signed-off-by: Justin Ruggles <justin.ruggles@gmail.com>
    
commit c509f4f74713b035a06f79cb4d00e708f5226bc5
-2
expand_less