You've already forked FFmpeg
mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2025-08-15 14:13:16 +02:00
Check for invalid slice offsets in real decoder.
Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
This commit is contained in:
committed by
Michael Niedermayer
parent
a254452472
commit
8716c178dd
@@ -1492,8 +1492,9 @@ int ff_rv34_decode_frame(AVCodecContext *avctx,
|
|||||||
slice_count = avctx->slice_count;
|
slice_count = avctx->slice_count;
|
||||||
|
|
||||||
//parse first slice header to check whether this frame can be decoded
|
//parse first slice header to check whether this frame can be decoded
|
||||||
if(get_slice_offset(avctx, slices_hdr, 0) > buf_size){
|
if(get_slice_offset(avctx, slices_hdr, 0) < 0 ||
|
||||||
av_log(avctx, AV_LOG_ERROR, "Slice offset is greater than frame size\n");
|
get_slice_offset(avctx, slices_hdr, 0) > buf_size){
|
||||||
|
av_log(avctx, AV_LOG_ERROR, "Slice offset is invalid\n");
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
init_get_bits(&s->gb, buf+get_slice_offset(avctx, slices_hdr, 0), (buf_size-get_slice_offset(avctx, slices_hdr, 0))*8);
|
init_get_bits(&s->gb, buf+get_slice_offset(avctx, slices_hdr, 0), (buf_size-get_slice_offset(avctx, slices_hdr, 0))*8);
|
||||||
@@ -1516,8 +1517,8 @@ int ff_rv34_decode_frame(AVCodecContext *avctx,
|
|||||||
else
|
else
|
||||||
size = get_slice_offset(avctx, slices_hdr, i+1) - offset;
|
size = get_slice_offset(avctx, slices_hdr, i+1) - offset;
|
||||||
|
|
||||||
if(offset > buf_size){
|
if(offset < 0 || offset > buf_size || size < 0){
|
||||||
av_log(avctx, AV_LOG_ERROR, "Slice offset is greater than frame size\n");
|
av_log(avctx, AV_LOG_ERROR, "Slice offset is invalid\n");
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user