shithub: libtags

Download patch

ref: d4799a66d117da0dbc275eb1becec2088643201d
parent: 2dcaa4af26a51d0d022f9ec6d2a7ad490d0e87d7
author: Sigrid Solveig Haflínudóttir <[email protected]>
date: Tue Mar 5 00:14:05 EST 2024

wav: validate value size as well

--- a/wav.c
+++ b/wav.c
@@ -47,7 +47,7 @@
 			break;
 		sz -= 4+4;
 		csz = leuint(d+4);
-		if(sz < csz)
+		if(sz < csz || csz < 0)
 			break;
 		sz -= csz;