[FFmpeg-cvslog] avformat/cafdec: dont seek beyond 64bit

2024-04-14 Thread Michael Niedermayer
ffmpeg | branch: release/2.8 | Michael Niedermayer  | 
Sat Sep 30 00:38:17 2023 +0200| [cf051d0750e7195d69d7ad0fd9fcd06461a5a361] | 
committer: Michael Niedermayer

avformat/cafdec: dont seek beyond 64bit

Fixes: signed integer overflow: 64 + 9223372036854775807 cannot be represented 
in type 'long long'
Fixes: 
51896/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064
Fixes: 
62276/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064

Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer 
(cherry picked from commit d973fcbcc2f944752ff10e6a76b0b2d9329937a7)
Signed-off-by: Michael Niedermayer 

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=cf051d0750e7195d69d7ad0fd9fcd06461a5a361
---

 libavformat/cafdec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/cafdec.c b/libavformat/cafdec.c
index ee46d19bbe..d22fab8d7f 100644
--- a/libavformat/cafdec.c
+++ b/libavformat/cafdec.c
@@ -214,7 +214,7 @@ static int read_pakt_chunk(AVFormatContext *s, int64_t size)
 }
 }
 
-if (avio_tell(pb) - ccount > size) {
+if (avio_tell(pb) - ccount > size || size > INT64_MAX - ccount) {
 av_log(s, AV_LOG_ERROR, "error reading packet table\n");
 return AVERROR_INVALIDDATA;
 }

___
ffmpeg-cvslog mailing list
ffmpeg-cvslog@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog

To unsubscribe, visit link above, or email
ffmpeg-cvslog-requ...@ffmpeg.org with subject "unsubscribe".


[FFmpeg-cvslog] avformat/cafdec: dont seek beyond 64bit

2024-04-14 Thread Michael Niedermayer
ffmpeg | branch: release/3.4 | Michael Niedermayer  | 
Sat Sep 30 00:38:17 2023 +0200| [2eb0e9d16898c6c4f54bb0e6075e4e3f6a84f18d] | 
committer: Michael Niedermayer

avformat/cafdec: dont seek beyond 64bit

Fixes: signed integer overflow: 64 + 9223372036854775807 cannot be represented 
in type 'long long'
Fixes: 
51896/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064
Fixes: 
62276/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064

Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer 
(cherry picked from commit d973fcbcc2f944752ff10e6a76b0b2d9329937a7)
Signed-off-by: Michael Niedermayer 

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=2eb0e9d16898c6c4f54bb0e6075e4e3f6a84f18d
---

 libavformat/cafdec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/cafdec.c b/libavformat/cafdec.c
index 3c6d6922a0..c74d3dc481 100644
--- a/libavformat/cafdec.c
+++ b/libavformat/cafdec.c
@@ -222,7 +222,7 @@ static int read_pakt_chunk(AVFormatContext *s, int64_t size)
 }
 }
 
-if (avio_tell(pb) - ccount > size) {
+if (avio_tell(pb) - ccount > size || size > INT64_MAX - ccount) {
 av_log(s, AV_LOG_ERROR, "error reading packet table\n");
 return AVERROR_INVALIDDATA;
 }

___
ffmpeg-cvslog mailing list
ffmpeg-cvslog@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog

To unsubscribe, visit link above, or email
ffmpeg-cvslog-requ...@ffmpeg.org with subject "unsubscribe".


[FFmpeg-cvslog] avformat/cafdec: dont seek beyond 64bit

2024-04-14 Thread Michael Niedermayer
ffmpeg | branch: release/4.2 | Michael Niedermayer  | 
Sat Sep 30 00:38:17 2023 +0200| [119eb87952d5bc403d946c79a1a7490022823ebc] | 
committer: Michael Niedermayer

avformat/cafdec: dont seek beyond 64bit

Fixes: signed integer overflow: 64 + 9223372036854775807 cannot be represented 
in type 'long long'
Fixes: 
51896/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064
Fixes: 
62276/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064

Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer 
(cherry picked from commit d973fcbcc2f944752ff10e6a76b0b2d9329937a7)
Signed-off-by: Michael Niedermayer 

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=119eb87952d5bc403d946c79a1a7490022823ebc
---

 libavformat/cafdec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/cafdec.c b/libavformat/cafdec.c
index b1db03a893..d823b3347d 100644
--- a/libavformat/cafdec.c
+++ b/libavformat/cafdec.c
@@ -222,7 +222,7 @@ static int read_pakt_chunk(AVFormatContext *s, int64_t size)
 }
 }
 
-if (avio_tell(pb) - ccount > size) {
+if (avio_tell(pb) - ccount > size || size > INT64_MAX - ccount) {
 av_log(s, AV_LOG_ERROR, "error reading packet table\n");
 return AVERROR_INVALIDDATA;
 }

___
ffmpeg-cvslog mailing list
ffmpeg-cvslog@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog

To unsubscribe, visit link above, or email
ffmpeg-cvslog-requ...@ffmpeg.org with subject "unsubscribe".


[FFmpeg-cvslog] avformat/cafdec: dont seek beyond 64bit

2024-04-14 Thread Michael Niedermayer
ffmpeg | branch: release/4.4 | Michael Niedermayer  | 
Sat Sep 30 00:38:17 2023 +0200| [625ca605f5b1f60f6409949533bcff8982d61464] | 
committer: Michael Niedermayer

avformat/cafdec: dont seek beyond 64bit

Fixes: signed integer overflow: 64 + 9223372036854775807 cannot be represented 
in type 'long long'
Fixes: 
51896/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064
Fixes: 
62276/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064

Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer 
(cherry picked from commit d973fcbcc2f944752ff10e6a76b0b2d9329937a7)
Signed-off-by: Michael Niedermayer 

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=625ca605f5b1f60f6409949533bcff8982d61464
---

 libavformat/cafdec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/cafdec.c b/libavformat/cafdec.c
index 1842c3c0ae..296e07c085 100644
--- a/libavformat/cafdec.c
+++ b/libavformat/cafdec.c
@@ -220,7 +220,7 @@ static int read_pakt_chunk(AVFormatContext *s, int64_t size)
 }
 }
 
-if (avio_tell(pb) - ccount > size) {
+if (avio_tell(pb) - ccount > size || size > INT64_MAX - ccount) {
 av_log(s, AV_LOG_ERROR, "error reading packet table\n");
 return AVERROR_INVALIDDATA;
 }

___
ffmpeg-cvslog mailing list
ffmpeg-cvslog@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog

To unsubscribe, visit link above, or email
ffmpeg-cvslog-requ...@ffmpeg.org with subject "unsubscribe".


[FFmpeg-cvslog] avformat/cafdec: dont seek beyond 64bit

2024-04-14 Thread Michael Niedermayer
ffmpeg | branch: release/5.1 | Michael Niedermayer  | 
Sat Sep 30 00:38:17 2023 +0200| [f0e780370cc1c437d64f10d326b1d656ef490b5f] | 
committer: Michael Niedermayer

avformat/cafdec: dont seek beyond 64bit

Fixes: signed integer overflow: 64 + 9223372036854775807 cannot be represented 
in type 'long long'
Fixes: 
51896/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064
Fixes: 
62276/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064

Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer 
(cherry picked from commit d973fcbcc2f944752ff10e6a76b0b2d9329937a7)
Signed-off-by: Michael Niedermayer 

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=f0e780370cc1c437d64f10d326b1d656ef490b5f
---

 libavformat/cafdec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/cafdec.c b/libavformat/cafdec.c
index e0a9031cb8..395f542a4c 100644
--- a/libavformat/cafdec.c
+++ b/libavformat/cafdec.c
@@ -265,7 +265,7 @@ static int read_pakt_chunk(AVFormatContext *s, int64_t size)
 }
 }
 
-if (avio_tell(pb) - ccount > size) {
+if (avio_tell(pb) - ccount > size || size > INT64_MAX - ccount) {
 av_log(s, AV_LOG_ERROR, "error reading packet table\n");
 return AVERROR_INVALIDDATA;
 }

___
ffmpeg-cvslog mailing list
ffmpeg-cvslog@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog

To unsubscribe, visit link above, or email
ffmpeg-cvslog-requ...@ffmpeg.org with subject "unsubscribe".


[FFmpeg-cvslog] avformat/cafdec: dont seek beyond 64bit

2024-04-14 Thread Michael Niedermayer
ffmpeg | branch: release/6.0 | Michael Niedermayer  | 
Sat Sep 30 00:38:17 2023 +0200| [e53481496737509526cc276d34a9f4c0d6260ecb] | 
committer: Michael Niedermayer

avformat/cafdec: dont seek beyond 64bit

Fixes: signed integer overflow: 64 + 9223372036854775807 cannot be represented 
in type 'long long'
Fixes: 
51896/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064
Fixes: 
62276/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064

Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer 
(cherry picked from commit d973fcbcc2f944752ff10e6a76b0b2d9329937a7)
Signed-off-by: Michael Niedermayer 

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=e53481496737509526cc276d34a9f4c0d6260ecb
---

 libavformat/cafdec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/cafdec.c b/libavformat/cafdec.c
index e0a9031cb8..395f542a4c 100644
--- a/libavformat/cafdec.c
+++ b/libavformat/cafdec.c
@@ -265,7 +265,7 @@ static int read_pakt_chunk(AVFormatContext *s, int64_t size)
 }
 }
 
-if (avio_tell(pb) - ccount > size) {
+if (avio_tell(pb) - ccount > size || size > INT64_MAX - ccount) {
 av_log(s, AV_LOG_ERROR, "error reading packet table\n");
 return AVERROR_INVALIDDATA;
 }

___
ffmpeg-cvslog mailing list
ffmpeg-cvslog@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog

To unsubscribe, visit link above, or email
ffmpeg-cvslog-requ...@ffmpeg.org with subject "unsubscribe".


[FFmpeg-cvslog] avformat/cafdec: dont seek beyond 64bit

2024-04-13 Thread Michael Niedermayer
ffmpeg | branch: release/6.1 | Michael Niedermayer  | 
Sat Sep 30 00:38:17 2023 +0200| [d66b1af8df7902a3b6226f13410112d9ff27bfc4] | 
committer: Michael Niedermayer

avformat/cafdec: dont seek beyond 64bit

Fixes: signed integer overflow: 64 + 9223372036854775807 cannot be represented 
in type 'long long'
Fixes: 
51896/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064
Fixes: 
62276/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064

Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer 
(cherry picked from commit d973fcbcc2f944752ff10e6a76b0b2d9329937a7)
Signed-off-by: Michael Niedermayer 

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=d66b1af8df7902a3b6226f13410112d9ff27bfc4
---

 libavformat/cafdec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/cafdec.c b/libavformat/cafdec.c
index f5ba0f4108..e92e3279fc 100644
--- a/libavformat/cafdec.c
+++ b/libavformat/cafdec.c
@@ -271,7 +271,7 @@ static int read_pakt_chunk(AVFormatContext *s, int64_t size)
 }
 }
 
-if (avio_tell(pb) - ccount > size) {
+if (avio_tell(pb) - ccount > size || size > INT64_MAX - ccount) {
 av_log(s, AV_LOG_ERROR, "error reading packet table\n");
 return AVERROR_INVALIDDATA;
 }

___
ffmpeg-cvslog mailing list
ffmpeg-cvslog@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog

To unsubscribe, visit link above, or email
ffmpeg-cvslog-requ...@ffmpeg.org with subject "unsubscribe".


[FFmpeg-cvslog] avformat/cafdec: dont seek beyond 64bit

2024-03-25 Thread Michael Niedermayer
ffmpeg | branch: master | Michael Niedermayer  | Sat 
Sep 30 00:38:17 2023 +0200| [d973fcbcc2f944752ff10e6a76b0b2d9329937a7] | 
committer: Michael Niedermayer

avformat/cafdec: dont seek beyond 64bit

Fixes: signed integer overflow: 64 + 9223372036854775807 cannot be represented 
in type 'long long'
Fixes: 
51896/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064
Fixes: 
62276/clusterfuzz-testcase-minimized-ffmpeg_dem_CAF_fuzzer-6418242730328064

Found-by: continuous fuzzing process 
https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer 

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=d973fcbcc2f944752ff10e6a76b0b2d9329937a7
---

 libavformat/cafdec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/libavformat/cafdec.c b/libavformat/cafdec.c
index 426c56b9bd..72809fd1de 100644
--- a/libavformat/cafdec.c
+++ b/libavformat/cafdec.c
@@ -271,7 +271,7 @@ static int read_pakt_chunk(AVFormatContext *s, int64_t size)
 }
 }
 
-if (avio_tell(pb) - ccount > size) {
+if (avio_tell(pb) - ccount > size || size > INT64_MAX - ccount) {
 av_log(s, AV_LOG_ERROR, "error reading packet table\n");
 return AVERROR_INVALIDDATA;
 }

___
ffmpeg-cvslog mailing list
ffmpeg-cvslog@ffmpeg.org
https://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog

To unsubscribe, visit link above, or email
ffmpeg-cvslog-requ...@ffmpeg.org with subject "unsubscribe".