mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2024-12-23 12:43:46 +02:00
dirac_parser: check prev_pu_offset before using it
Fixes out of array read Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
This commit is contained in:
parent
fef75ef200
commit
2b643855e0
@ -161,7 +161,9 @@ static int dirac_combine_frame(AVCodecParserContext *s, AVCodecContext *avctx,
|
||||
* we can be pretty sure that we have a valid parse unit */
|
||||
if (!unpack_parse_unit(&pu1, pc, pc->index - 13) ||
|
||||
!unpack_parse_unit(&pu, pc, pc->index - 13 - pu1.prev_pu_offset) ||
|
||||
pu.next_pu_offset != pu1.prev_pu_offset) {
|
||||
pu.next_pu_offset != pu1.prev_pu_offset ||
|
||||
pc->index < pc->dirac_unit_size + 13LL + pu1.prev_pu_offset
|
||||
) {
|
||||
pc->index -= 9;
|
||||
*buf_size = next-9;
|
||||
pc->header_bytes_needed = 9;
|
||||
|
Loading…
Reference in New Issue
Block a user