Module: libav Branch: release/9 Commit: 62f9253781fa4534f10f8dbb0a2fea9377a8c87e
Author: Anton Khirnov <[email protected]> Committer: Reinhard Tartler <[email protected]> Date: Wed Mar 27 18:18:38 2013 +0100 dfa: check for invalid access in decode_wdlt(). This can happen when the number of skipped lines is not consistent with the number of coded lines. Reported-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind CC: [email protected] (cherry picked from commit 3623589edc7b1257bb45aa9e52c9631e133f22b6) Signed-off-by: Reinhard Tartler <[email protected]> --- libavcodec/dfa.c | 2 ++ 1 files changed, 2 insertions(+), 0 deletions(-) diff --git a/libavcodec/dfa.c b/libavcodec/dfa.c index 119be70..332a53e 100644 --- a/libavcodec/dfa.c +++ b/libavcodec/dfa.c @@ -257,6 +257,8 @@ static int decode_wdlt(GetByteContext *gb, uint8_t *frame, int width, int height segments = bytestream2_get_le16(gb); } line_ptr = frame; + if (frame_end - frame < width) + return AVERROR_INVALIDDATA; frame += width; y++; while (segments--) { _______________________________________________ libav-commits mailing list [email protected] https://lists.libav.org/mailman/listinfo/libav-commits
