Module: libav
Branch: release/0.7
Commit: b6783b882682a95633b6db70ee80fffe61168256

Author:    Michael Niedermayer <[email protected]>
Committer: Reinhard Tartler <[email protected]>
Date:      Sat Apr 14 20:04:05 2012 +0200

indeo5: update AVCodecContext width/height on size change

Fixes CVE-2012-2787

Note that in 0.7, there is only indeo 5, no indeo 4 decoder

Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: Anton Khirnov <[email protected]>
(cherry picked from commit b146d74730ab9ec5abede9066f770ad851e45fbc)

Signed-off-by: Reinhard Tartler <[email protected]>
(cherry picked from commit 2bc1e4fcb96c470e2ccb2a0a78a415d5eab960c8)

Conflicts:

        libavcodec/ivi_common.c

---

 libavcodec/indeo5.c |    1 +
 1 files changed, 1 insertions(+), 0 deletions(-)

diff --git a/libavcodec/indeo5.c b/libavcodec/indeo5.c
index 45460a4..bdb53ca 100644
--- a/libavcodec/indeo5.c
+++ b/libavcodec/indeo5.c
@@ -798,6 +798,7 @@ static int decode_frame(AVCodecContext *avctx, void *data, 
int *data_size,
         avctx->release_buffer(avctx, &ctx->frame);
 
     ctx->frame.reference = 0;
+    avcodec_set_dimensions(avctx, ctx->planes[0].width, ctx->planes[0].height);
     if (avctx->get_buffer(avctx, &ctx->frame) < 0) {
         av_log(avctx, AV_LOG_ERROR, "get_buffer() failed\n");
         return -1;

_______________________________________________
libav-commits mailing list
[email protected]
https://lists.libav.org/mailman/listinfo/libav-commits

Reply via email to