--- lib/codebook.c | 1 + 1 file changed, 1 insertion(+) --- a/lib/codebook.c +++ b/lib/codebook.c @@ -198,6 +198,7 @@ for(i=0;ientries;){ long num=oggpack_read(opb,_ilog(s->entries-i)); if(num==-1)goto _eofout; + if(length>32)goto _errout; for(j=0;jentries;j++,i++) s->lengthlist[i]=length; length++;