Skip to content

reject oversized entry counts in stco/co64/stss/stsc/stts/stsz - #458

Open
Chandan3456 wants to merge 1 commit into
mozilla:masterfrom
Chandan3456:stbl-entry-count-guard
Open

Chandan3456 wants to merge 1 commit into
mozilla:masterfrom
Chandan3456:stbl-entry-count-guard

Conversation

@Chandan3456

Copy link
Copy Markdown

read_ctts already rejects a ctts box whose declared entry count needs more bytes than the box holds, before it preallocates. reading through the sibling sample table parsers i noticed read_stco, read_co64, read_stss, read_stsc, read_stts and read_stsz skip that check -- each takes the u32 count straight off the wire and hands it to TryVec::with_capacity (or reserve) before reading a single entry, so a 16-byte stco claiming 0xffffffff offsets asks for a multi-gigabyte allocation for entries that cannot be present. i added the same count*entry_size against bytes_left guard read_ctts uses to each of them, behind one shared StblBadEntryCount status, plus a regression test. the check only fires when the declared count exceeds what the box can hold, so files with trailing padding are unaffected.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant