1
0
mirror of https://github.com/FFmpeg/FFmpeg.git synced 2025-01-03 05:10:03 +02:00
FFmpeg/libavcodec
Michael Niedermayer adb0a29111 avcodec/hevc_ps: Check log2_sao_offset_scale_*
Fixes: 4868/clusterfuzz-testcase-minimized-6236542906400768
Fixes: runtime error: shift exponent 126 is too large for 32-bit type 'int'

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 4a75a75c62)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
2018-02-19 02:40:54 +01:00
..
aarch64
alpha
arm avcodec/arm/sbrdsp_neon: Use a free register instead of putting 2 things in one 2018-02-19 02:40:54 +01:00
avr32
bfin
mips
neon
ppc
sh4
sparc
x86 avcodec/x86/mpegvideodsp: Fix signedness bug in need_emu 2017-12-02 00:28:59 +01:00
4xm.c
8bps.c avcodec/8bps: Check side data size before use 2016-12-04 20:25:15 +01:00
8svx.c
012v.c
a64colors.h
a64multienc.c
a64tables.h
aac_ac3_parser.c
aac_ac3_parser.h
aac_adtstoasc_bsf.c
aac_defines.h avcodec/aacdec_template: Fix undefined integer overflow in apply_tns() 2017-07-19 03:54:39 +02:00
aac_parser.c
aac.h
aacadtsdec.c
aacadtsdec.h
aaccoder_trellis.h
aaccoder_twoloop.h
aaccoder.c
aacdec_fixed.c avcodec/aacdec_fixed: Fix undefined shift 2017-12-02 00:28:59 +01:00
aacdec_template.c avcodec/aacdec_template: Clear tns present flag on error 2017-10-05 01:29:45 +02:00
aacdec.c avcodec/aacdec: Fix runtime error: signed integer overflow: 2147483520 + 255 cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
aacdectab.h
aacenc_is.c
aacenc_is.h
aacenc_ltp.c
aacenc_ltp.h
aacenc_pred.c
aacenc_pred.h
aacenc_quantization_misc.h
aacenc_quantization.h
aacenc_tns.c
aacenc_tns.h
aacenc_utils.h
aacenc.c
aacenc.h
aacenctab.c
aacenctab.h
aacps_fixed_tablegen.c
aacps_fixed_tablegen.h
aacps_fixed.c
aacps_float.c
aacps_tablegen_template.c
aacps_tablegen.c
aacps_tablegen.h
aacps.c avcodec/aacps: Fix multiple integer overflow in map_val_34_to_20() 2017-07-26 00:14:03 +02:00
aacps.h
aacpsdata.c
aacpsdsp_fixed.c
aacpsdsp_float.c
aacpsdsp_template.c avcodec/aacpsdsp_template: Fix integer overflows in ps_decorrelate_c() 2017-12-02 00:28:59 +01:00
aacpsdsp.h
aacpsy.c
aacsbr_fixed_tablegen.h
aacsbr_fixed.c avcodec/aacsbr_fixed: Fix division by zero in sbr_gain_calc() 2017-12-02 00:28:59 +01:00
aacsbr_tablegen_common.h
aacsbr_tablegen.h
aacsbr_template.c avcodec/aacsbr_template: Do not change bs_num_env before its checked 2017-05-17 20:35:20 +02:00
aacsbr.c
aacsbr.h
aacsbrdata.h
aactab.c
aactab.h
aandcttab.c
aandcttab.h
aasc.c
ac3_parser.c
ac3_parser.h
ac3.c
ac3.h
ac3dec_data.c
ac3dec_data.h
ac3dec_fixed.c avcodec/ac3dec_fixed: Fix integer overflow in scale_coefs() 2018-02-19 02:40:54 +01:00
ac3dec_float.c
ac3dec.c avcodec/ac3dec: Fix: runtime error: index -1 out of bounds for type 'INTFLOAT [2]' 2017-05-17 20:35:20 +02:00
ac3dec.h avcodec/ac3dec: Keep track of band structure 2017-05-17 20:35:20 +02:00
ac3dsp.c
ac3dsp.h
ac3enc_fixed.c
ac3enc_float.c
ac3enc_opts_template.c
ac3enc_template.c
ac3enc.c
ac3enc.h
ac3tab.c
ac3tab.h
acelp_filters.c
acelp_filters.h
acelp_pitch_delay.c avcodec/acelp_pitch_delay: Fix runtime error: value 4.83233e+39 is outside the range of representable values of type 'float' 2017-05-31 02:44:40 +02:00
acelp_pitch_delay.h
acelp_vectors.c
acelp_vectors.h
adpcm_data.c
adpcm_data.h
adpcm.c
adpcm.h
adpcmenc.c
adx_parser.c
adx.c
adx.h
adxdec.c avcodec/adxdec: Fix runtime error: left shift of negative value -1 2017-05-17 20:35:19 +02:00
adxenc.c
aic.c
alac_data.c
alac_data.h
alac.c
alacdsp.c
alacdsp.h
alacenc.c
aliaspixdec.c
aliaspixenc.c
allcodecs.c
alsdec.c
amr.h
amrnbdata.h
amrnbdec.c
amrwbdata.h
amrwbdec.c avcodec/amrwbdec: Fix division by 0 in voice_factor() 2018-02-19 02:40:54 +01:00
anm.c
ansi.c avcodec/ansi: Fix frame memleak 2017-05-31 02:43:15 +02:00
apedec.c avcodec/apedec: Fix integer overflow 2017-07-16 17:02:31 +02:00
apng.h
ass_split.c
ass_split.h
ass.c
ass.h
assdec.c
assenc.c
asv.c
asv.h
asvdec.c
asvenc.c
atrac1.c
atrac1data.h
atrac3.c
atrac3data.h
atrac3plus_data.h
atrac3plus.c
atrac3plus.h
atrac3plusdec.c
atrac3plusdsp.c
atrac.c
atrac.h
audio_frame_queue.c
audio_frame_queue.h
audioconvert.c
audioconvert.h
audiodsp.c
audiodsp.h
aura.c
avcodec.h avcodec/avcodec: Limit the number of side data elements per packet 2017-05-17 20:35:20 +02:00
avcodecres.rc
avdct.c
avdct.h
avfft.c
avfft.h
avpacket.c avcodec/avcodec: Limit the number of side data elements per packet 2017-05-17 20:35:20 +02:00
avpicture.c
avrndec.c
avs.c
avuidec.c
avuienc.c
bethsoftvideo.c
bethsoftvideo.h
bfi.c
bgmc.c
bgmc.h
bink.c
binkaudio.c
binkdata.h
binkdsp.c
binkdsp.h
bintext.c
bintext.h
bit_depth_template.c
bitstream_filter.c
bitstream.c
blockdsp.c
blockdsp.h
bmp_parser.c
bmp.c
bmp.h
bmpenc.c
bmvaudio.c
bmvvideo.c avcodec/bmvvideo: Fix runtime error: left shift of 137 by 24 places cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
brenderpix.c
bswapdsp.c
bswapdsp.h
bytestream.h
c93.c
cabac_functions.h
cabac.c
cabac.h
canopus.c
canopus.h
cavs_parser.c
cavs.c avcodec/cavs: Fix runtime error: signed integer overflow: -12648062 * 256 cannot be represented in type 'int' 2017-06-20 02:05:08 +02:00
cavs.h
cavsdata.c
cavsdec.c avcodec/cavsdec: Fix runtime error: signed integer overflow: 59 + 2147483600 cannot be represented in type 'int' 2017-06-04 00:27:10 +02:00
cavsdsp.c
cavsdsp.h
cbrt_fixed_tablegen.c
cbrt_tablegen_template.c
cbrt_tablegen.c
cbrt_tablegen.h
ccaption_dec.c
cdgraphics.c
cdxl.c avcodec/cdxl: Check format for BGR24 2017-05-17 20:35:20 +02:00
celp_filters.c
celp_filters.h
celp_math.c
celp_math.h
cfhd.c avcodec/cfhd: Fix decoding regression due to height check 2017-07-23 15:00:53 +02:00
cfhd.h
cfhddata.c
cga_data.c
cga_data.h
chomp_bsf.c
cinepak.c avcodec/cinepak: Check input packet size before frame reallocation 2017-06-04 00:29:23 +02:00
cinepakenc.c
cljrdec.c
cljrenc.c
cllc.c avcodec/cllc: Check prefix 2017-05-17 20:35:20 +02:00
cngdec.c avcodec/cngdec: Fix integer clipping 2017-12-02 00:28:59 +01:00
cngenc.c
codec_desc.c
cook_parser.c
cook.c
cookdata.h
copy_block.h
cos_tablegen.c
cpia.c
crystalhd.c
cscd.c
cyuv.c
d3d11va.c
d3d11va.h
dca_core.c
dca_core.h
dca_exss.c
dca_exss.h
dca_parser.c
dca_syncwords.h
dca_xll.c
dca_xll.h
dca.c
dca.h
dcadata.c
dcadata.h
dcadct.c
dcadct.h
dcadec.c
dcadec.h
dcadsp.c avcodec/dcadsp: Fix runtime error: signed integer overflow 2017-05-17 20:35:19 +02:00
dcadsp.h
dcaenc.c
dcaenc.h
dcahuff.h
dcamath.h
dct32_fixed.c
dct32_float.c
dct32_template.c
dct32.h
dct-test.c
dct.c
dct.h
dctref.c
dctref.h
dds.c avcodec/dds: Fix runtime error: left shift of 210 by 24 places cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
dfa.c avcodec/dfa: Fix: runtime error: signed integer overflow: -14202 * 196877 cannot be represented in type 'int' 2017-05-18 12:36:32 +02:00
dirac_arith.c
dirac_arith.h
dirac_dwt_template.c avcodec/dirac_dwt_template: Fix integer overflow in vertical_compose53iL0() 2017-08-21 23:27:09 +02:00
dirac_dwt.c
dirac_dwt.h avcodec/dirac_dwt: Fix overflows in COMPOSE_HAARiH0/COMPOSE_HAARiL0 2018-02-19 02:40:54 +01:00
dirac_parser.c
dirac.c
dirac.h
diracdec.c avcodec/diracdec: Fix integer overflow with quant 2018-02-19 02:40:54 +01:00
diracdsp.c avcodec/diracdsp: Fix integer overflow in PUT_SIGNED_RECT_CLAMPED() 2018-02-19 02:40:54 +01:00
diracdsp.h
diractab.c
diractab.h
dnxhd_parser.c
dnxhddata.c
dnxhddata.h
dnxhddec.c avcodec/dnxhddec: Check dc vlc 2018-02-19 02:40:54 +01:00
dnxhdenc.c
dnxhdenc.h
dpcm.c
dpx_parser.c
dpx.c
dpxenc.c
dsd_tablegen.h
dsddec.c
dsicinaudio.c
dsicinvideo.c
dss_sp.c avcodec/dss_sp: Fix runtime error: signed integer overflow: 2147481189 + 4096 cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
dump_extradata_bsf.c
dv_profile_internal.h
dv_profile.c
dv_profile.h
dv_tablegen.c
dv_tablegen.h
dv.c
dv.h
dvaudio_parser.c
dvaudio.h
dvaudiodec.c
dvbsub_parser.c
dvbsub.c
dvbsubdec.c avcodec/dvbsubdec: Check entry_id 2017-05-17 20:35:20 +02:00
dvd_nav_parser.c
dvdata.c
dvdata.h
dvdec.c
dvdsub_parser.c
dvdsubdec.c avcodec/dvdsubdec: Fix runtime error: left shift of 242 by 24 places cannot be represented in type 'int' 2017-05-17 20:35:19 +02:00
dvdsubenc.c
dvenc.c
dxa.c
dxtory.c avcodec/dxtory: Fix bits left checks 2018-02-19 02:40:54 +01:00
dxv.c avcodec/dxv: Check remaining bytes in dxv_decompress_raw() 2017-06-05 03:31:29 +02:00
dxva2_h264.c
dxva2_hevc.c
dxva2_internal.h
dxva2_mpeg2.c
dxva2_vc1.c
dxva2_vp9.c
dxva2.c
dxva2.h
eac3_data.c
eac3_data.h
eac3dec.c avcodec/eac3dec: Fix runtime error: left shift of negative value -3 2017-05-17 20:35:19 +02:00
eac3enc.c
eac3enc.h
eacmv.c
eaidct.c
eaidct.h
eamad.c avcodec/eamad: Fix runtime error: signed integer overflow: 49674 * 49858 cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
eatgq.c
eatgv.c
eatqi.c avcodec/eatqi: Fix runtime error: signed integer overflow: 4466147 * 1075 cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
elbg.c
elbg.h
elsdec.c
elsdec.h
error_resilience.c
error_resilience.h
escape124.c escape124: reject codebook size 0 2016-11-27 00:38:56 +01:00
escape130.c
evrcdata.h
evrcdec.c
exif.c
exif.h
exr.c avcodec/exr: Check buf_size more completely 2018-02-19 02:40:54 +01:00
faandct.c
faandct.h
faanidct.c
faanidct.h
faxcompr.c
faxcompr.h
fdctdsp.c
fdctdsp.h
fft_fixed_32.c
fft_fixed.c
fft_float.c
fft_init_table.c
fft_table.h
fft_template.c
fft-fixed32-test.c
fft-fixed-test.c
fft-internal.h
fft-test.c
fft.h
ffv1.c
ffv1.h
ffv1dec.c avcodec/ffv1dec: Fix out of array read in slice counting 2017-10-13 13:02:24 +02:00
ffv1enc.c avcodec/ffv1enc: Allocate smaller packet if the worst case size cannot be allocated 2016-12-09 21:39:14 +01:00
ffwavesynth.c
fic.c avcodec/fic: Fixes signed integer overflow 2017-08-21 23:27:08 +02:00
file_open.c
flac_parser.c avcodec/flac_parser: Update nb_headers_buffered 2016-12-04 20:25:15 +01:00
flac.c
flac.h
flacdata.c
flacdata.h
flacdec.c avcodec/flacdec: Fix overflow in multiplication in decode_subframe_fixed() 2018-02-19 02:40:54 +01:00
flacdsp_lpc_template.c
flacdsp_template.c avcodec/flacdsp_template: Fix undefined shift in flac_decorrelate_indep_c 2016-12-04 20:25:15 +01:00
flacdsp.c
flacdsp.h
flacenc.c
flashsv2enc.c
flashsv.c
flashsvenc.c
flicvideo.c avcodec/flicvideo: Fix runtime error: signed integer overflow: 4864 * 459296 cannot be represented in type 'int' 2017-06-20 02:05:08 +02:00
flv.h
flvdec.c
flvenc.c
fmtconvert.c
fmtconvert.h
frame_thread_encoder.c
frame_thread_encoder.h
fraps.c
frwu.c
g2meet.c
g722.c avcodec/g722: Fix multiple runtime error: left shift of negative value -1 2017-05-17 20:35:19 +02:00
g722.h
g722dec.c
g722dsp.c
g722dsp.h
g722enc.c
g723_1.c avcodec/g723_1: Fix multiple runtime error: left shift of negative value 2017-05-17 20:35:19 +02:00
g723_1.h avcodec/g723_1: Fix multiple runtime error: left shift of negative value 2017-05-17 20:35:19 +02:00
g723_1dec.c avcodec/g723_1dec: Fix LCG type 2017-05-17 20:35:20 +02:00
g723_1enc.c
g726.c avcodec/g726: Fix runtime error: left shift of negative value -2 2017-05-17 20:35:20 +02:00
g729_parser.c
g729.h
g729data.h
g729dec.c
g729postfilter.c
g729postfilter.h
get_bits.h avcodec/get_bits: Document the return code of get_vlc2() 2018-02-19 02:40:54 +01:00
gif.c
gif.h
gifdec.c
golomb-test.c
golomb.c
golomb.h
gsm_parser.c
gsm.h
gsmdec_data.c
gsmdec_data.h
gsmdec_template.c
gsmdec.c
h261_parser.c
h261.c
h261.h
h261data.c
h261dec.c
h261enc.c
h263_parser.c
h263_parser.h
h263.c
h263.h
h263data.c
h263data.h
h263dec.c
h263dsp.c
h263dsp.h
h264_cabac.c avcodec/h264: Fix mix of lossless and lossy MBs decoding 2017-06-20 03:09:09 +02:00
h264_cavlc.c avcodec/h264: Fix mix of lossless and lossy MBs decoding 2017-06-20 03:09:09 +02:00
h264_direct.c avcodec/h264_direct: Fix runtime error: left shift of negative value -14 2017-05-17 20:35:19 +02:00
h264_loopfilter.c
h264_mb_template.c
h264_mb.c avcodec/h264_mb: Fix 8x8dct in lossless for new versions of x264 2017-06-20 03:04:29 +02:00
h264_mc_template.c
h264_mp4toannexb_bsf.c
h264_mvpred.h avcodec/h264_mvpred: Fix runtime error: left shift of negative value -1 2017-05-17 20:35:19 +02:00
h264_parser.c
h264_picture.c
h264_ps.c
h264_refs.c
h264_sei.c
h264_slice.c avcodec/h264_slice: Do not attempt to render into frames already output 2018-02-19 02:40:54 +01:00
h264.c avcodec/h264_slice: Clear ref_counts on redundant slices 2017-02-08 20:08:22 +01:00
h264.h avcodec/h264dec: Fix potential array overread 2017-12-02 00:28:59 +01:00
h264addpx_template.c avcodec/h264addpx_template: Fixes integer overflows 2018-02-19 02:40:54 +01:00
h264chroma_template.c
h264chroma.c
h264chroma.h
h264data.h
h264dsp_template.c
h264dsp.c
h264dsp.h
h264idct_template.c avcodec/h264idct_template: Fix integer overflows in ff_h264_idct8_add() 2017-12-02 00:28:59 +01:00
h264idct.c
h264idct.h
h264pred_template.c
h264pred.c
h264pred.h
h264qpel_template.c
h264qpel.c
h264qpel.h
hap.c
hap.h
hapdec.c
hapenc.c
hevc_cabac.c avcodec/hevc_cabac: Check prefix so as to avoid invalid shifts in coeff_abs_level_remaining_decode() 2018-02-19 02:40:54 +01:00
hevc_data.c
hevc_filter.c avcodec/hevc_filter: Fix invalid shift 2017-06-22 03:08:45 +02:00
hevc_mp4toannexb_bsf.c
hevc_mvs.c
hevc_parse.c
hevc_parser.c
hevc_ps_enc.c
hevc_ps.c avcodec/hevc_ps: Check log2_sao_offset_scale_* 2018-02-19 02:40:54 +01:00
hevc_refs.c avcodec/hevc_refs: Check nb_refs in add_candidate_ref() 2017-06-20 02:05:09 +02:00
hevc_sei.c avcodec/hevc_sei: Fix integer overflows in decode_nal_sei_message() 2018-02-19 02:40:54 +01:00
hevc.c avcodec/hevcdec: Fix signed integer overflow in decode_lt_rps() 2017-06-20 02:05:09 +02:00
hevc.h avcodec/hevc_ps: extract one SPS fields required for hvcC construction 2018-02-19 02:40:54 +01:00
hevcdsp_template.c avcodec/hevcdsp_template: Fix Invalid shifts in put_hevc_qpel_bi_w_h() and put_hevc_qpel_bi_w_w() 2018-02-19 02:40:54 +01:00
hevcdsp.c
hevcdsp.h
hevcpred_template.c avcodec/hevcpred_template: Fix left shift of negative value 2017-06-20 02:05:09 +02:00
hevcpred.c
hevcpred.h
hnm4video.c
hpel_template.c
hpeldsp.c
hpeldsp.h
hq_hqa.c avcodec/hq_hqa: Fix: runtime error: signed integer overflow: -255 * 10180917 cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
hq_hqa.h
hq_hqadata.c
hq_hqadsp.c
hq_hqadsp.h
hqx.c
hqx.h
hqxdsp.c avcodec/hqxdsp: Fix runtime error: signed integer overflow: -196264 * 11585 cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
hqxdsp.h
hqxvlc.c
htmlsubtitles.c avcodec/htmlsubtitles: Replace very slow redundant sscanf() calls by cleaner and faster code 2017-06-22 03:06:43 +02:00
htmlsubtitles.h avcodec/htmlsubtitles: Check for string truncation and return error 2017-05-17 20:35:20 +02:00
huffman.c
huffman.h
huffyuv.c
huffyuv.h
huffyuvdec.c
huffyuvdsp.c
huffyuvdsp.h
huffyuvenc.c
huffyuvencdsp.c
huffyuvencdsp.h
idcinvideo.c avcodec/idcinvideo: Check side data size before use 2016-12-04 20:25:15 +01:00
idctdsp.c
idctdsp.h
iff.c
iirfilter.c
iirfilter.h
imc.c
imcdata.h
imdct15.c
imdct15.h
imgconvert.c
imx_dump_header_bsf.c
indeo2.c avcodec/indeo2: Check for invalid VLCs 2017-05-17 20:35:20 +02:00
indeo2data.h
indeo3.c
indeo3data.h
indeo4.c avcodec/indeo4: Check remaining data in Pic hdr extension parsing code 2017-06-20 02:05:08 +02:00
indeo4data.h
indeo5.c
indeo5data.h
intelh263dec.c
internal.h
interplayacm.c
interplayvideo.c avcodec/interplayvideo: Move parameter change check up 2017-02-04 03:05:08 +01:00
intrax8.c
intrax8.h
intrax8dsp.c
intrax8dsp.h
intrax8huf.h
ituh263dec.c avcodec/ituh263dec: Fix runtime error: left shift of negative value -22 2017-05-17 20:35:19 +02:00
ituh263enc.c
ivi_dsp.c avcodec/ivi_dsp: Fix runtime error: left shift of negative value -2 2017-05-28 04:04:09 +02:00
ivi_dsp.h
ivi.c
ivi.h
j2kenc.c avcodec/j2kenc: Fix out of array access in encode_cblk() 2017-12-02 00:28:59 +01:00
jacosub.h
jacosubdec.c
jfdctfst.c
jfdctint_template.c
jfdctint.c
jpeg2000.c avcodec/jpeg2000: Check that codsty->log2_prec_widths/heights has been initialized 2017-10-05 01:26:58 +02:00
jpeg2000.h avcodec/jpeg2000: Fixes integer overflow in ff_jpeg2000_ceildivpow2() 2017-06-20 02:05:09 +02:00
jpeg2000dec.c avcodec/jpeg2000dec: Check nonzerobits more completely 2017-06-20 02:05:09 +02:00
jpeg2000dsp.c avcodec/jpeg2000dsp: Fix integer overflows in ict_int() 2018-02-19 02:40:54 +01:00
jpeg2000dsp.h
jpeg2000dwt.c avcodec/jpeg2000dwt: Fix integer overflow in dwt_decode97_int() 2017-07-19 02:45:52 +02:00
jpeg2000dwt.h
jpegls.c
jpegls.h
jpeglsdec.c avcodec/jpeglsdec: Check for end of bitstream in ls_decode_line() 2017-12-02 00:28:59 +01:00
jpeglsdec.h
jpeglsenc.c
jpegtables.c
jpegtables.h
jrevdct.c
jvdec.c
kbdwin.c
kbdwin.h
kgv1dec.c avcodec/kgv1dec: Check that there is enough input for maximum RLE compression 2017-12-02 00:28:59 +01:00
kmvc.c avcodec/kmvc: Check side data size before use 2016-12-04 20:25:15 +01:00
lagarith.c avcodec/lagarith: Check scale_factor 2017-05-17 20:35:20 +02:00
lagarithrac.c
lagarithrac.h
latm_parser.c
lcl.h
lcldec.c
lclenc.c
libavcodec.v
libcelt_dec.c
libdcadec.c
libfaac.c
libfdk-aacdec.c avcodec/libfdk-aacdec: Correct buffer_size parameter 2017-05-28 04:06:03 +02:00
libfdk-aacenc.c
libgsmdec.c
libgsmenc.c
libilbc.c
libkvazaar.c
libmp3lame.c
libopencore-amr.c
libopenh264enc.c
libopenjpegdec.c
libopenjpegenc.c
libopus.c
libopus.h
libopusdec.c libopusdec: default to stereo for invalid number of channels 2016-11-27 00:38:57 +01:00
libopusenc.c
libschroedinger.c
libschroedinger.h
libschroedingerdec.c libschroedingerdec: fix leaking of framewithpts 2016-11-27 00:38:57 +01:00
libschroedingerenc.c
libshine.c
libspeexdec.c
libspeexenc.c
libtheoraenc.c
libtwolame.c
libutvideo.h
libutvideodec.cpp
libutvideoenc.cpp
libvo-amrwbenc.c
libvorbisdec.c
libvorbisenc.c
libvpx.c
libvpx.h
libvpxdec.c
libvpxenc.c
libwavpackenc.c
libwebpenc_animencoder.c
libwebpenc_common.c
libwebpenc_common.h
libwebpenc.c
libx264.c
libx265.c
libxavs.c
libxvid_rc.c
libxvid.c
libxvid.h
libzvbi-teletextdec.c
ljpegenc.c
loco.c
log2_tab.c
lossless_audiodsp.c
lossless_audiodsp.h
lossless_videodsp.c
lossless_videodsp.h
lpc.c
lpc.h avcodec/lpc: signed integer overflow in compute_lpc_coefs() (aacdec_fixed) 2017-06-22 03:08:23 +02:00
lsp.c
lsp.h
lzf.c
lzf.h
lzw.c
lzw.h
lzwenc.c
mace.c
Makefile
mathops.c
mathops.h
mathtables.c
mdct_fixed_32.c
mdct_fixed.c avcodec/mdct_*: Fix integer overflow in addition in RESCALE() 2017-12-02 00:28:59 +01:00
mdct_float.c
mdct_template.c avcodec/mdct_*: Fix integer overflow in addition in RESCALE() 2017-12-02 00:28:59 +01:00
mdec.c avcodec/mdec: Fix signed integer overflow: 28835400 * 83 cannot be represented in type 'int' 2017-05-17 20:35:19 +02:00
me_cmp.c avcodec/me_cmp: Fix crashes on ARM due to misalignment 2017-08-21 23:27:09 +02:00
me_cmp.h
metasound_data.c
metasound_data.h
metasound.c
microdvddec.c
mimic.c avcodec/mimic: Use ff_set_dimensions() to set the dimensions 2017-05-18 18:11:52 +02:00
mjpeg2jpeg_bsf.c
mjpeg_parser.c
mjpeg.h
mjpega_dump_header_bsf.c
mjpegbdec.c
mjpegdec.c avcodec/mjpegdec: Fix integer overflow in DC dequantization 2018-02-19 02:40:54 +01:00
mjpegdec.h
mjpegenc_common.c
mjpegenc_common.h
mjpegenc.c
mjpegenc.h
mlp_parser.c
mlp_parser.h
mlp.c
mlp.h
mlpdec.c avcodec/mlpdec: Do not leave invalid values in matrix_out_ch[] on error 2017-05-27 15:00:50 +02:00
mlpdsp.c avcodec/mlpdsp: Fix signed integer overflow, 2nd try 2017-12-02 00:28:59 +01:00
mlpdsp.h
mmaldec.c
mmvideo.c
motion_est_template.c
motion_est.c
motion_est.h
motion-test.c
motionpixels_tablegen.c
motionpixels_tablegen.h
motionpixels.c
movsub_bsf.c
movtextdec.c avcodec/movtextdec: Fix decode_styl() cleanup 2017-02-06 12:11:39 +01:00
movtextenc.c
mp3_header_decompress_bsf.c
mpc7.c
mpc7data.h
mpc8.c
mpc8data.h
mpc8huff.h
mpc.c
mpc.h
mpcdata.h
mpeg4_unpack_bframes_bsf.c
mpeg4audio.c
mpeg4audio.h
mpeg4data.h
mpeg4video_parser.c
mpeg4video_parser.h
mpeg4video.c
mpeg4video.h
mpeg4videodec.c avcodec/mpeg4videodec: Avoid possibly aliasing violating casts 2018-02-19 02:40:54 +01:00
mpeg4videoenc.c
mpeg12.c
mpeg12.h
mpeg12data.c
mpeg12data.h
mpeg12dec.c avcodec/mpeg12dec: Fixes runtime error: division by zero 2017-05-17 20:35:20 +02:00
mpeg12enc.c
mpeg12vlc.h
mpeg_er.c avcodec/mpeg_er: Clear mcsel in mpeg_er_decode_mb() 2017-10-13 12:59:48 +02:00
mpeg_er.h
mpegaudio_parser.c
mpegaudio_tablegen.c
mpegaudio_tablegen.h
mpegaudio.c
mpegaudio.h
mpegaudiodata.c
mpegaudiodata.h
mpegaudiodec_fixed.c
mpegaudiodec_float.c
mpegaudiodec_template.c avcodec/mpegaudiodec_template: Make l3_unscale() work with e=0 2017-05-17 20:35:19 +02:00
mpegaudiodecheader.c
mpegaudiodecheader.h
mpegaudiodectab.h
mpegaudiodsp_data.c
mpegaudiodsp_fixed.c
mpegaudiodsp_float.c
mpegaudiodsp_template.c
mpegaudiodsp.c Use ff_thread_once for fixed, float table init. 2017-12-02 00:28:59 +01:00
mpegaudiodsp.h
mpegaudioenc_fixed.c
mpegaudioenc_float.c
mpegaudioenc_template.c
mpegaudiotab.h
mpegpicture.c
mpegpicture.h
mpegutils.c
mpegutils.h
mpegvideo_enc.c avcodec/mpegvideo_enc: Clear mmx state in ff_mpv_reallocate_putbitbuffer() 2016-12-04 20:25:15 +01:00
mpegvideo_motion.c avcodec/mpeg4video: Fix runtime error: left shift of negative value 2017-05-17 20:35:19 +02:00
mpegvideo_parser.c
mpegvideo_xvmc.c
mpegvideo.c
mpegvideo.h
mpegvideodata.c
mpegvideodata.h
mpegvideodsp.c
mpegvideodsp.h
mpegvideoencdsp.c
mpegvideoencdsp.h
mpl2dec.c
mqc.c
mqc.h
mqcdec.c
mqcenc.c
msgsmdec.c
msgsmdec.h
msmpeg4.c
msmpeg4.h
msmpeg4data.c
msmpeg4data.h
msmpeg4dec.c avcodec/msmpeg4dec: Check for cbpy VLC errors 2017-05-17 20:35:20 +02:00
msmpeg4enc.c
msrle.c avcodec/msrle: Check side data size before use 2016-12-04 20:25:15 +01:00
msrledec.c
msrledec.h
mss1.c
mss2.c mss2: only use error correction for matching block counts 2016-11-27 00:38:58 +01:00
mss2dsp.c
mss2dsp.h
mss3.c avcodec/mss3: Change types in rac_get_model_sym() to match the types they are initialized from 2017-05-17 20:35:19 +02:00
mss4.c
mss12.c
mss12.h
mss34dsp.c avcodec/mss34dsp: Fix multiple signed integer overflow 2017-05-17 20:35:19 +02:00
mss34dsp.h
msvideo1.c avcodec/msvideo1: Check buffer size before re-getting the frame 2017-05-17 20:35:19 +02:00
msvideo1enc.c
mvcdec.c
mxpegdec.c
nellymoser.c avcodec/nellymoser: Fix multiple left shift of negative value -8591 2017-05-17 20:35:19 +02:00
nellymoser.h
nellymoserdec.c
nellymoserenc.c
noise_bsf.c
nuv.c
nvenc.c
on2avc.c
on2avcdata.c
on2avcdata.h
options_table.h
options.c avcodec/options: do a more thorough clean up in avcodec_copy_context() 2017-05-17 16:26:06 -03:00
opus_celt.c
opus_parser.c avcodec/opus_parser: Check payload_len in parse_opus_ts_header() 2018-02-19 02:40:54 +01:00
opus_silk.c avcodec/opus_silk: Fix integer overflow and out of array read 2017-05-17 20:35:20 +02:00
opus.c
opus.h
opusdec.c
paf.h
pafaudio.c
pafvideo.c avcodec/pafvideo: Check for bitstream end in decode_0() 2017-10-15 00:45:11 +02:00
pamenc.c
parser.c
parser.h
pcm_tablegen.c
pcm_tablegen.h
pcm-bluray.c
pcm-dvd.c
pcm.c
pcx.c
pcxenc.c
pel_template.c
pgssubdec.c pgssubdec: reset rle_data_len/rle_remaining_len on allocation error 2017-02-01 02:28:56 +01:00
pictordec.c avcodec/pictordec: Check plane value before doing value/mask computations 2017-05-17 20:35:19 +02:00
pixblockdsp.c avcodec/me_cmp: Fix crashes on ARM due to misalignment 2017-08-21 23:27:09 +02:00
pixblockdsp.h avcodec/me_cmp: Fix crashes on ARM due to misalignment 2017-08-21 23:27:09 +02:00
pixels.h
png_parser.c
png.c
png.h
pngdec.c avcodec/pngdec: Clean up on av_frame_ref() failure 2017-09-20 03:09:15 +02:00
pngdsp.c
pngdsp.h
pngenc.c
pnm_parser.c
pnm.c avcodec/pnm: Use ff_set_dimensions() 2017-06-04 00:28:05 +02:00
pnm.h
pnmdec.c pnmdec: make sure v is capped by maxval 2016-11-27 00:38:57 +01:00
pnmenc.c
profiles.c
profiles.h
proresdata.c
proresdata.h
proresdec2.c avcodec/proresdec2: SKIP_BITS() does not work with len=32 2017-10-05 01:28:22 +02:00
proresdec_lgpl.c proresdec_lgpl: explicitly check coff[3] against slice_data_size 2016-11-27 00:38:56 +01:00
proresdec.h
proresdsp.c
proresdsp.h
proresenc_anatoliy.c
proresenc_kostya.c
psymodel.c
psymodel.h
pthread_frame.c
pthread_internal.h
pthread_slice.c
pthread.c
ptx.c
put_bits.h
qcelpdata.h
qcelpdec.c
qdm2_tablegen.c
qdm2_tablegen.h
qdm2.c
qdm2data.h
qdrw.c avcodec/qdrw: Fix null pointer dereference 2017-06-05 03:33:56 +02:00
qpeg.c avcodec/qpeg: Check side data size before use 2016-12-04 20:25:15 +01:00
qpel_template.c
qpeldsp.c
qpeldsp.h
qsv_api.c
qsv_internal.h
qsv.c
qsv.h
qsvdec_h2645.c
qsvdec_mpeg2.c
qsvdec_vc1.c
qsvdec.c
qsvdec.h
qsvenc_h264.c
qsvenc_hevc.c
qsvenc_mpeg2.c
qsvenc.c
qsvenc.h
qtrle.c avcodec/qtrle: Check side data size before use 2016-12-04 20:25:15 +01:00
qtrleenc.c
r210dec.c
r210enc.c
ra144.c avcodec/ra144: Fix runtime error: signed integer overflow: -2200 * 1033073 cannot be represented in type 'int' 2017-06-20 02:05:08 +02:00
ra144.h
ra144dec.c avcodec/ra144dec: Fix runtime error: left shift of negative value -17 2017-05-27 15:00:25 +02:00
ra144enc.c
ra288.c
ra288.h
ralf.c
ralfdata.h
rangecoder.c
rangecoder.h
ratecontrol.c
ratecontrol.h
raw.c
raw.h
rawdec.c avcodec/rawdec: check for side data before checking its size 2016-12-04 17:27:07 -03:00
rawenc.c
rdft.c
rdft.h
realtextdec.c
rectangle.h
remove_extradata_bsf.c
resample2.c
resample.c
reverse.c
rl2.c
rl.c
rl.h
rle.c
rle.h
rnd_avg.h
roqaudioenc.c
roqvideo.c
roqvideo.h
roqvideodec.c
roqvideoenc.c
rpza.c
rscc.c avcodec/rscc: Check pixel_size for overflow 2017-05-17 20:35:20 +02:00
rtjpeg.c
rtjpeg.h
rv10.c
rv10.h
rv10enc.c
rv20enc.c
rv30.c
rv30data.h
rv30dsp.c
rv34_parser.c
rv34.c avcodec/rv34: Fix runtime error: signed integer overflow: 36880 * 66288 cannot be represented in type 'int' 2017-05-17 20:35:19 +02:00
rv34.h
rv34data.h
rv34dsp.c
rv34dsp.h
rv34vlc.h
rv40.c avcodec/rv40: Fix runtime error: left shift of negative value 2017-05-17 20:35:19 +02:00
rv40data.h
rv40dsp.c avcodec/rv40: Fix runtime error: left shift of negative value 2017-05-17 20:35:19 +02:00
rv40vlc2.h
s302m.c avcodec/s302m: Fix left shift of 8 by 28 places cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
s302menc.c
samidec.c
sanm.c avcodec/sanm: Fix uninitialized reference frames 2017-05-24 15:53:16 +02:00
sbr.h
sbrdsp_fixed.c avcodec/sbrdsp_fixed: Fix integer overflow in shift in sbr_hf_g_filt_c() 2017-12-02 00:28:59 +01:00
sbrdsp_template.c avcodec/sbrdsp_template: Fix: runtime error: signed integer overflow: 849815297 + 1315389781 cannot be represented in type 'int' 2017-05-28 04:05:39 +02:00
sbrdsp.c
sbrdsp.h
screenpresso.c
sgi.h
sgidec.c
sgienc.c
sgirledec.c
shorten.c avcodec/shorten: Sanity check maxnlpc 2017-06-20 02:05:09 +02:00
simple_idct_template.c
simple_idct.c
simple_idct.h
sinewin_fixed_tablegen.c
sinewin_fixed.c
sinewin_tablegen_template.c
sinewin_tablegen.c
sinewin_tablegen.h
sinewin.c
sinewin.h
sipr16k.c
sipr16kdata.h
sipr.c
sipr.h
siprdata.h
smacker.c smacker: limit recursion depth of smacker_decode_bigtree 2016-11-27 00:38:57 +01:00
smc.c avcodec/smc: Check remaining input 2017-05-26 12:28:08 +02:00
smvjpegdec.c smvjpegdec: make sure cur_frame is not negative 2016-11-27 00:38:57 +01:00
snappy.c
snappy.h
snow_dwt.c
snow_dwt.h
snow.c
snow.h avcodec/snow: Fix runtime error: signed integer overflow: 1086573993 + 1086573994 cannot be represented in type 'int' 2017-05-31 02:38:02 +02:00
snowdata.h
snowdec.c avcodec/snowdec: Fix integer overflow before htaps check 2018-02-19 02:40:54 +01:00
snowenc.c
sonic.c
sp5x.h
sp5xdec.c
srtdec.c avcodec/srtdec: Fix signed integer overflow: 1811992524 * 384 cannot be represented in type 'int' 2017-05-17 20:35:19 +02:00
srtenc.c
startcode.c
startcode.h
subviewerdec.c
sunrast.c avcodec/sunrast: Fix input buffer pointer check 2016-12-04 20:25:15 +01:00
sunrast.h
sunrastenc.c
svq1_cb.h
svq1_vlc.h
svq1.c
svq1.h
svq1dec.c
svq1enc_cb.h
svq1enc.c
svq1enc.h
svq3.c avcodec/svq3: Fix overflow in svq3_add_idct_c() 2017-09-24 02:41:00 +02:00
svq3.h
svq13.c
synth_filter.c
synth_filter.h
tableprint_vlc.h
tableprint.h
tak_parser.c
tak.c
tak.h
takdec.c avcodec/takdec: Fix integer overflow in decode_lpc() 2017-09-25 11:10:30 +02:00
takdsp.c
takdsp.h
targa_y216dec.c avcodec/targa_y216dec: Fix width type 2017-05-17 20:35:19 +02:00
targa.c
targa.h
targaenc.c
tdsc.c
textdec.c
texturedsp.c avcodec/texturedsp: Fix runtime error: left shift of 255 by 24 places cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
texturedsp.h
texturedspenc.c
thread.h
tiertexseqv.c avcodec/tiertexseqv: set the fixed dimenasions, do not depend on the demuxer doing so 2017-05-17 20:35:19 +02:00
tiff_common.c
tiff_common.h
tiff_data.c
tiff_data.h
tiff.c avcodec/tiff: Update pointer only when the result is used 2017-06-23 03:05:34 +02:00
tiff.h
tiffenc.c
tmv.c
tpeldsp.c
tpeldsp.h
truemotion1.c avcodec/truemotion1: Fix multiple runtime error: signed integer overflow: 1246906962 * 2 cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
truemotion1data.h
truemotion2.c avcodec/truemotion2: Fix integer overflow in TM2_RECALC_BLOCK() 2018-02-19 02:40:54 +01:00
truespeech_data.h
truespeech.c
tscc2.c
tscc2data.h
tscc.c avcodec/tscc: Check side data size before use 2016-12-04 20:25:15 +01:00
tta.c
ttadata.c
ttadata.h
ttadsp.c
ttadsp.h
ttaenc.c
twinvq_data.h
twinvq.c
twinvq.h
twinvqdec.c
txd.c
ulti_cb.h
ulti.c avcodec/ulti: Check number of blocks at init 2018-02-19 02:40:54 +01:00
unary.h
utils.c avcodec/utils: Avoid hardcoding duplicated types in sizeof() 2018-02-19 02:40:54 +01:00
utvideo.c
utvideo.h
utvideodec.c
utvideoenc.c
v210dec.c
v210dec.h
v210enc.c
v210enc.h
v210x.c
v308dec.c
v308enc.c
v408dec.c
v408enc.c
v410dec.c
v410enc.c
vaapi_h264.c
vaapi_hevc.c
vaapi_internal.h
vaapi_mpeg2.c
vaapi_mpeg4.c
vaapi_vc1.c
vaapi_vp9.c
vaapi.c
vaapi.h
vb.c avcodec/vb: Check vertical GMC component before multiply 2017-07-19 02:48:40 +02:00
vble.c
vc1_block.c
vc1_common.h
vc1_loopfilter.c
vc1_mc.c
vc1_parser.c
vc1_pred.c
vc1_pred.h
vc1.c
vc1.h
vc1acdata.h
vc1data.c
vc1data.h
vc1dec.c
vc1dsp.c
vc1dsp.h
vc2enc_dwt.c vc2enc_dwt: pad the temporary buffer by the slice size 2017-11-09 02:09:53 +00:00
vc2enc_dwt.h vc2enc_dwt: pad the temporary buffer by the slice size 2017-11-09 02:09:53 +00:00
vc2enc.c avcodec/vc2enc: Clear coef_buf on allocation 2017-12-02 00:28:59 +01:00
vcr1.c
vda_h264_dec.c
vda_h264.c
vda_vt_internal.h
vda.c
vda.h
vdpau_compat.h
vdpau_h264.c
vdpau_hevc.c avcodec/vdpau_hevc: Fix potential out-of-bounds write 2017-05-17 20:35:19 +02:00
vdpau_internal.h
vdpau_mpeg4.c
vdpau_mpeg12.c
vdpau_vc1.c
vdpau.c
vdpau.h
version.h
videodsp_template.c
videodsp.c
videodsp.h
videotoolbox.c
videotoolbox.h
vima.c
vmdaudio.c
vmdvideo.c
vmnc.c avcodec/vmnc: Check location before use 2017-05-21 14:53:17 +02:00
vorbis_data.c
vorbis_enc_data.h
vorbis_parser_internal.h
vorbis_parser.c
vorbis_parser.h
vorbis.c avcodec/vorbis: Fix another 1 << 31 > int32_t::max() with 1u. 2017-12-02 00:28:59 +01:00
vorbis.h
vorbisdec.c
vorbisdsp.c
vorbisdsp.h
vorbisenc.c
vp3_parser.c
vp3.c avcodec/vp3: Check remaining bits in unpack_dct_coeffs() 2017-05-17 20:35:19 +02:00
vp3data.h
vp3dsp.c avcodec/vp3dsp: Fix multiple signed integer overflow: 46341 * 47523 cannot be represented in type 'int' 2017-05-17 20:35:19 +02:00
vp3dsp.h
vp5.c avcodec/vp568: Check that there is enough data for ff_vp56_init_range_decoder() 2017-05-17 20:35:19 +02:00
vp5data.h
vp6.c avcodec/vp6: clear dimensions on failed resolution change in vp6_parse_header() 2017-05-17 20:35:19 +02:00
vp6data.h
vp6dsp.c
vp8_parser.c
vp8.c avcodec/webp: Always set pix_fmt 2017-05-17 20:35:20 +02:00
vp8.h avcodec/vp8: Check for bitsteam end in decode_mb_row_no_filter() 2017-05-17 20:35:19 +02:00
vp8data.h
vp8dsp.c avcodec/vp8dsp: vp7_luma_dc_wht_c: Fix multiple runtime error: signed integer overflow: -1366381240 + -1262413604 cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
vp8dsp.h
vp9_mc_template.c
vp9_parser.c
vp9.c avcodec/vp568: Check that there is enough data for ff_vp56_init_range_decoder() 2017-05-17 20:35:19 +02:00
vp9.h
vp9data.h
vp9dsp_8bpp.c
vp9dsp_10bpp.c
vp9dsp_12bpp.c
vp9dsp_template.c
vp9dsp.c
vp9dsp.h
vp56.c avcodec/vp56: Check avctx->error_concealment before enabling EC 2017-05-17 20:35:19 +02:00
vp56.h avcodec/vp568: Check that there is enough data for ff_vp56_init_range_decoder() 2017-05-17 20:35:19 +02:00
vp56data.c
vp56data.h
vp56dsp.c
vp56dsp.h
vp56rac.c avcodec/vp568: Check that there is enough data for ff_vp56_init_range_decoder() 2017-05-17 20:35:19 +02:00
vqavideo.c
wavpack.c avcodec/wavpack: Fix invalid shift 2017-07-19 02:50:35 +02:00
wavpack.h avcodec/wavpack: Fix runtime error: signed integer overflow: 1886191616 + 277872640 cannot be represented in type 'int' 2017-06-20 02:05:09 +02:00
wavpackenc.c
wavpackenc.h
webp.c avcodec/webp: Fixes null pointer dereference 2017-05-31 02:39:20 +02:00
webvttdec.c
webvttenc.c
wma_common.c
wma_common.h
wma_freqs.c
wma_freqs.h
wma.c
wma.h
wmadata.h
wmadec.c
wmaenc.c
wmalosslessdec.c
wmaprodata.h
wmaprodec.c
wmavoice_data.h
wmavoice.c
wmv2.c
wmv2.h
wmv2dec.c avcodec/wmv2dec: Check end of bitstream in parse_mb_skip() and ff_wmv2_decode_mb() 2017-12-02 00:28:59 +01:00
wmv2dsp.c avcodec/wmv2dsp: Fix runtime error: signed integer overflow: 181 * -17047030 cannot be represented in type 'int' 2017-05-17 20:35:20 +02:00
wmv2dsp.h
wmv2enc.c
wnv1.c avcodec/wnv1: More strict buffer size check 2017-05-28 04:08:56 +02:00
wrapped_avframe.c
ws-snd1.c
xan.c avcodec/xan: Check for bitstream end in xan_huffman_decode() 2017-12-02 00:28:59 +01:00
xbmdec.c
xbmenc.c
xface.c
xface.h
xfacedec.c
xfaceenc.c
xiph.c
xiph.h
xl.c
xsubdec.c
xsubenc.c
xvididct.c
xvididct.h
xvmc_internal.h
xvmc.h
xwd.h
xwddec.c avcodec/xwddec: Check bpp more completely 2017-05-17 20:35:20 +02:00
xwdenc.c
xxan.c
y41pdec.c avcodec/y41pdec: Fix width in input buffer size check 2017-05-17 20:35:20 +02:00
y41penc.c
yop.c
yuv4dec.c
yuv4enc.c
zerocodec.c
zmbv.c avcodec/zmbv: Check that the buffer is large enough for mvec 2017-12-02 00:28:59 +01:00
zmbvenc.c