You've already forked FFmpeg
mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2025-11-23 21:54:53 +02:00
avcodec/mscc & mwsc: Check loop counts before use
This could cause timeouts Fixes: CID1439568 Untrusted loop bound Sponsored-by: Sovereign Tech Fund Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
@@ -54,6 +54,9 @@ static int rle_uncompress(AVCodecContext *avctx, GetByteContext *gb, PutByteCont
|
|||||||
unsigned run = bytestream2_get_byte(gb);
|
unsigned run = bytestream2_get_byte(gb);
|
||||||
|
|
||||||
if (run) {
|
if (run) {
|
||||||
|
if (bytestream2_get_bytes_left_p(pb) < run * s->bpp)
|
||||||
|
return AVERROR_INVALIDDATA;
|
||||||
|
|
||||||
switch (avctx->bits_per_coded_sample) {
|
switch (avctx->bits_per_coded_sample) {
|
||||||
case 8:
|
case 8:
|
||||||
fill = bytestream2_get_byte(gb);
|
fill = bytestream2_get_byte(gb);
|
||||||
@@ -102,6 +105,9 @@ static int rle_uncompress(AVCodecContext *avctx, GetByteContext *gb, PutByteCont
|
|||||||
|
|
||||||
bytestream2_seek_p(pb, y * avctx->width * s->bpp + x * s->bpp, SEEK_SET);
|
bytestream2_seek_p(pb, y * avctx->width * s->bpp + x * s->bpp, SEEK_SET);
|
||||||
} else {
|
} else {
|
||||||
|
if (bytestream2_get_bytes_left_p(pb) < copy * s->bpp)
|
||||||
|
return AVERROR_INVALIDDATA;
|
||||||
|
|
||||||
for (j = 0; j < copy; j++) {
|
for (j = 0; j < copy; j++) {
|
||||||
switch (avctx->bits_per_coded_sample) {
|
switch (avctx->bits_per_coded_sample) {
|
||||||
case 8:
|
case 8:
|
||||||
|
|||||||
@@ -51,6 +51,10 @@ static int rle_uncompress(GetByteContext *gb, PutByteContext *pb, GetByteContext
|
|||||||
|
|
||||||
if (run == 0) {
|
if (run == 0) {
|
||||||
run = bytestream2_get_le32(gb);
|
run = bytestream2_get_le32(gb);
|
||||||
|
|
||||||
|
if (bytestream2_tell_p(pb) + width - w < run)
|
||||||
|
return AVERROR_INVALIDDATA;
|
||||||
|
|
||||||
for (int j = 0; j < run; j++, w++) {
|
for (int j = 0; j < run; j++, w++) {
|
||||||
if (w == width) {
|
if (w == width) {
|
||||||
w = 0;
|
w = 0;
|
||||||
@@ -62,6 +66,10 @@ static int rle_uncompress(GetByteContext *gb, PutByteContext *pb, GetByteContext
|
|||||||
int pos = bytestream2_tell_p(pb);
|
int pos = bytestream2_tell_p(pb);
|
||||||
|
|
||||||
bytestream2_seek(gbp, pos, SEEK_SET);
|
bytestream2_seek(gbp, pos, SEEK_SET);
|
||||||
|
|
||||||
|
if (pos + width - w < fill)
|
||||||
|
return AVERROR_INVALIDDATA;
|
||||||
|
|
||||||
for (int j = 0; j < fill; j++, w++) {
|
for (int j = 0; j < fill; j++, w++) {
|
||||||
if (w == width) {
|
if (w == width) {
|
||||||
w = 0;
|
w = 0;
|
||||||
@@ -73,6 +81,9 @@ static int rle_uncompress(GetByteContext *gb, PutByteContext *pb, GetByteContext
|
|||||||
|
|
||||||
intra = 0;
|
intra = 0;
|
||||||
} else {
|
} else {
|
||||||
|
if (bytestream2_tell_p(pb) + width - w < run)
|
||||||
|
return AVERROR_INVALIDDATA;
|
||||||
|
|
||||||
for (int j = 0; j < run; j++, w++) {
|
for (int j = 0; j < run; j++, w++) {
|
||||||
if (w == width) {
|
if (w == width) {
|
||||||
w = 0;
|
w = 0;
|
||||||
|
|||||||
Reference in New Issue
Block a user