mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2025-01-24 13:56:33 +02:00
avformat/mov: Check STSC and remove invalid entries
Fixes assertion failure Fixes: crbug 822547, crbug 822666 and crbug 823009 Affects: aark15sd_9A62E2FA.mp4 Found-by: ClusterFuzz Reviewed-by: Matt Wolenetz <wolenetz@google.com> Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> (cherry picked from commit 9e67447a4ffacf28af8bace33faf3ea432ddc43e) Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
parent
b4e66382c2
commit
17f626528a
@ -2228,6 +2228,21 @@ static int mov_read_stsc(MOVContext *c, AVIOContext *pb, MOVAtom atom)
|
|||||||
}
|
}
|
||||||
|
|
||||||
sc->stsc_count = i;
|
sc->stsc_count = i;
|
||||||
|
for (i = sc->stsc_count - 1; i < UINT_MAX; i--) {
|
||||||
|
if ((i+1 < sc->stsc_count && sc->stsc_data[i].first >= sc->stsc_data[i+1].first) ||
|
||||||
|
(i > 0 && sc->stsc_data[i].first <= sc->stsc_data[i-1].first) ||
|
||||||
|
sc->stsc_data[i].first < 1 ||
|
||||||
|
sc->stsc_data[i].count < 1 ||
|
||||||
|
sc->stsc_data[i].id < 1) {
|
||||||
|
av_log(c->fc, AV_LOG_WARNING, "STSC entry %d is invalid (first=%d count=%d id=%d)\n", i, sc->stsc_data[i].first, sc->stsc_data[i].count, sc->stsc_data[i].id);
|
||||||
|
if (i+1 >= sc->stsc_count || sc->stsc_data[i+1].first < 2)
|
||||||
|
return AVERROR_INVALIDDATA;
|
||||||
|
// We replace this entry by the next valid
|
||||||
|
sc->stsc_data[i].first = sc->stsc_data[i+1].first - 1;
|
||||||
|
sc->stsc_data[i].count = sc->stsc_data[i+1].count;
|
||||||
|
sc->stsc_data[i].id = sc->stsc_data[i+1].id;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if (pb->eof_reached)
|
if (pb->eof_reached)
|
||||||
return AVERROR_EOF;
|
return AVERROR_EOF;
|
||||||
@ -3011,6 +3026,11 @@ static int mov_read_trak(MOVContext *c, AVIOContext *pb, MOVAtom atom)
|
|||||||
st->index);
|
st->index);
|
||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
if (sc->stsc_count && sc->stsc_data[ sc->stsc_count - 1 ].first > sc->chunk_count) {
|
||||||
|
av_log(c->fc, AV_LOG_ERROR, "stream %d, contradictionary STSC and STCO\n",
|
||||||
|
st->index);
|
||||||
|
return AVERROR_INVALIDDATA;
|
||||||
|
}
|
||||||
|
|
||||||
fix_timescale(c, sc);
|
fix_timescale(c, sc);
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user