Changes between Initial Version and Version 1 of Ticket #3721, comment 4


Ignore:
Timestamp:
Jun 17, 2014, 10:33:14 AM (7 years ago)
Author:
Alexander V. Lukyanov

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #3721, comment 4

    initial v1  
    1 It looks like a problem with format auto-detection. s->priv_data is not correctly allocated at util.c:577 (with priv_data_size=5912), but later it is assumed to be MpegTSContext and sizeof(MpegTSContext) = 73848, thus it overwrites memory past allocated buffer.
     1It looks like a problem with format auto-detection. s->priv_data is not correctly allocated at util.c:577 (with priv_data_size=5912, iformat=&ff_rtp_demuxer), but later it is assumed to be MpegTSContext and sizeof(MpegTSContext) = 73848, thus it overwrites memory past allocated buffer.
    22
    33When I run ffmpeg with explicit "-f mpegts" it correctly allocates priv_data_size=73848 and does not crash.