aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michaelni@gmx.at>2014-10-03 21:08:52 +0200
committerMichael Niedermayer <michaelni@gmx.at>2014-11-28 20:27:41 +0100
commiteac21ee7ba0f9a29f96a0abd219f00075cbd30d7 (patch)
tree2d42dcf114116d8307e4efa872bc2402517d00c0
parentb2f2cbdb1caf18e61b5b2666ae29afcf310c901e (diff)
downloadffmpeg-eac21ee7ba0f9a29f96a0abd219f00075cbd30d7.tar.gz
avcodec/qpeg: fix off by 1 error in MV bounds check
Fixes out of array access Fixes: asan_heap-oob_153760f_4_asan_heap-oob_1d7a4cf_164_VWbig6.avi Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind Signed-off-by: Michael Niedermayer <michaelni@gmx.at> (cherry picked from commit dd3bfe3cc1ca26d0fff3a3baf61a40207032143f) Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
-rw-r--r--libavcodec/qpeg.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/libavcodec/qpeg.c b/libavcodec/qpeg.c
index aa8f69c0cf..454c371ed5 100644
--- a/libavcodec/qpeg.c
+++ b/libavcodec/qpeg.c
@@ -165,7 +165,7 @@ static void qpeg_decode_inter(const uint8_t *src, uint8_t *dst, int size,
/* check motion vector */
if ((me_x + filled < 0) || (me_x + me_w + filled > width) ||
- (height - me_y - me_h < 0) || (height - me_y > orig_height) ||
+ (height - me_y - me_h < 0) || (height - me_y >= orig_height) ||
(filled + me_w > width) || (height - me_h < 0))
av_log(NULL, AV_LOG_ERROR, "Bogus motion vector (%i,%i), block size %ix%i at %i,%i\n",
me_x, me_y, me_w, me_h, filled, height);