diff options
author | Stefan Gehrer <stefan.gehrer@gmx.de> | 2006-07-14 18:38:23 +0000 |
---|---|---|
committer | Stefan Gehrer <stefan.gehrer@gmx.de> | 2006-07-14 18:38:23 +0000 |
commit | 643326f747cd841c58cb03a7902e0e134f94c62d (patch) | |
tree | 6911a220746a11b86fbb03f792468ecb7de946cf | |
parent | 3409385da635da8a36f93991ad016c25f66df68a (diff) | |
download | ffmpeg-643326f747cd841c58cb03a7902e0e134f94c62d.tar.gz |
avoid overflows of qp and pic_type
Originally committed as revision 5746 to svn://svn.ffmpeg.org/ffmpeg/trunk
-rw-r--r-- | libavcodec/cavs.c | 8 |
1 files changed, 6 insertions, 2 deletions
diff --git a/libavcodec/cavs.c b/libavcodec/cavs.c index 88b37f1610..7d5047b923 100644 --- a/libavcodec/cavs.c +++ b/libavcodec/cavs.c @@ -716,7 +716,7 @@ static inline int decode_residual_inter(AVSContext *h) { /* get quantizer */ if(h->cbp && !h->qp_fixed) - h->qp += get_se_golomb(&h->s.gb); + h->qp = (h->qp + get_se_golomb(&h->s.gb)) & 63; for(block=0;block<4;block++) if(h->cbp & (1<<block)) decode_residual_block(h,&h->s.gb,inter_2dvlc,0,h->qp, @@ -876,7 +876,7 @@ static int decode_mb_i(AVSContext *h, int cbp_code) { } h->cbp = cbp_tab[cbp_code][0]; if(h->cbp && !h->qp_fixed) - h->qp += get_se_golomb(gb); //qp_delta + h->qp = (h->qp + get_se_golomb(gb)) & 63; //qp_delta /* luma intra prediction interleaved with residual decode/transform/add */ for(block=0;block<4;block++) { @@ -1154,6 +1154,10 @@ static int decode_pic(AVSContext *h) { get_bits(&s->gb,16);//bbv_dwlay if(h->stc == PIC_PB_START_CODE) { h->pic_type = get_bits(&s->gb,2) + FF_I_TYPE; + if(h->pic_type > FF_B_TYPE) { + av_log(s->avctx, AV_LOG_ERROR, "illegal picture type\n"); + return -1; + } /* make sure we have the reference frames we need */ if(!h->DPB[0].data[0] || (!h->DPB[1].data[0] && h->pic_type == FF_B_TYPE)) |