1
0
mirror of https://github.com/FFmpeg/FFmpeg.git synced 2024-12-28 20:53:54 +02:00

avcodec/rscc: check input buffer size for deflate mode

Fixes overreads.

Reviewed-by: Michael Niedermayer <michael@niedermayer.cc>
Signed-off-by: James Almer <jamrial@gmail.com>
(cherry picked from commit b2244fa0a6)
This commit is contained in:
James Almer 2016-05-10 22:07:19 -03:00
parent 08c21bcb5d
commit 8dce66d33d

View File

@ -223,6 +223,12 @@ static int rscc_decode_frame(AVCodecContext *avctx, void *data,
ff_dlog(avctx, "pixel_size %d packed_size %d.\n", pixel_size, packed_size); ff_dlog(avctx, "pixel_size %d packed_size %d.\n", pixel_size, packed_size);
if (packed_size < 0) {
av_log(avctx, AV_LOG_ERROR, "Invalid tile size %d\n", packed_size);
ret = AVERROR_INVALIDDATA;
goto end;
}
/* Get pixels buffer, it may be deflated or just raw */ /* Get pixels buffer, it may be deflated or just raw */
if (pixel_size == packed_size) { if (pixel_size == packed_size) {
if (bytestream2_get_bytes_left(gbc) < pixel_size) { if (bytestream2_get_bytes_left(gbc) < pixel_size) {
@ -233,6 +239,11 @@ static int rscc_decode_frame(AVCodecContext *avctx, void *data,
pixels = gbc->buffer; pixels = gbc->buffer;
} else { } else {
uLongf len = ctx->inflated_size; uLongf len = ctx->inflated_size;
if (bytestream2_get_bytes_left(gbc) < packed_size) {
av_log(avctx, AV_LOG_ERROR, "Insufficient input for %d\n", packed_size);
ret = AVERROR_INVALIDDATA;
goto end;
}
ret = uncompress(ctx->inflated_buf, &len, gbc->buffer, packed_size); ret = uncompress(ctx->inflated_buf, &len, gbc->buffer, packed_size);
if (ret) { if (ret) {
av_log(avctx, AV_LOG_ERROR, "Pixel deflate error %d.\n", ret); av_log(avctx, AV_LOG_ERROR, "Pixel deflate error %d.\n", ret);