Skip the rest of an EIT section if any descriptor' s length exceeds event size
[email protected] (Daniel Kamil Kozar) Mon, 24 Aug 2015 12:54:41 +0200 (CEST)
| Newsgroups | gmane.comp.video.videolan.libdvbpsi.devel |
|---|---|
| Message-ID | <[email protected]> |
libdvbpsi | branch: master | Daniel Kamil Kozar <[email protected]> | Sat Jun 27 10:49:05 2015 +0200| [3d18f673a800f4551e69775e9800ff23b80690de] | committer: Jean-Paul Saman Skip the rest of an EIT section if any descriptor's length exceeds event size > http://git.videolan.org/gitweb.cgi/libdvbpsi.git/?a=commit;h=3d18f673a800f4551e69775e9800ff23b80690de --- src/tables/eit.c | 15 +++++++++++++-- src/tables/eit_private.h | 3 ++- 2 files changed, 15 insertions(+), 3 deletions(-) diff --git a/src/tables/eit.c b/src/tables/eit.c index fa1ae7e..0e75805 100644 --- a/src/tables/eit.c +++ b/src/tables/eit.c @@ -495,7 +495,8 @@ void dvbpsi_eit_sections_gather(dvbpsi_t *p_dvbpsi, dvbpsi_decoder_t *p_private_ p_eit_decoder->b_current_valid = true; /* Decode the sections */ - dvbpsi_eit_sections_decode(p_eit_decoder->p_building_eit, + dvbpsi_eit_sections_decode(p_dvbpsi, + p_eit_decoder->p_building_eit, p_eit_decoder->p_sections); /* signal the new EIT */ @@ -512,7 +513,8 @@ void dvbpsi_eit_sections_gather(dvbpsi_t *p_dvbpsi, dvbpsi_decoder_t *p_private_ ***************************************************************************** * EIT decoder. *****************************************************************************/ -void dvbpsi_eit_sections_decode(dvbpsi_eit_t* p_eit, +void dvbpsi_eit_sections_decode(dvbpsi_t *p_dvbpsi, + dvbpsi_eit_t* p_eit, dvbpsi_psi_section_t* p_section) { uint8_t* p_byte, *p_end; @@ -555,9 +557,18 @@ void dvbpsi_eit_sections_decode(dvbpsi_eit_t* p_eit, uint8_t i_length = p_byte[1]; if (i_length + 2 <= p_ev_end - p_byte) dvbpsi_eit_event_descriptor_add(p_event, i_tag, i_length, p_byte + 2); + else + { + dvbpsi_error(p_dvbpsi, "EIT decoder", "failed decoding " + "section %d : descriptor size exceeds event size", + p_section->i_number); + goto next_section; + } + p_byte += 2 + i_length; } } + next_section: p_section = p_section->p_next; } } diff --git a/src/tables/eit_private.h b/src/tables/eit_private.h index 498c2fa..03c4d66 100644 --- a/src/tables/eit_private.h +++ b/src/tables/eit_private.h @@ -61,7 +61,8 @@ void dvbpsi_eit_sections_gather(dvbpsi_t *p_dvbpsi, ***************************************************************************** * EIT decoder. *****************************************************************************/ -void dvbpsi_eit_sections_decode(dvbpsi_eit_t* p_eit, +void dvbpsi_eit_sections_decode(dvbpsi_t *p_dvbpsi, + dvbpsi_eit_t* p_eit, dvbpsi_psi_section_t* p_section); #else _______________________________________________ libdvbpsi-devel mailing list [email protected] https://mailman.videolan.org/listinfo/libdvbpsi-devel