aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michael@niedermayer.cc>2019-12-14 15:27:44 +0100
committerMichael Niedermayer <michael@niedermayer.cc>2020-05-19 17:17:35 +0200
commit0cfd3d6dd6afe5b6db35f4bba93d3de3b400c046 (patch)
treebb30a38c08b605f94afcf86655fd038f7cf8414e
parent06df6bfdb423f78637d795125eb2e0c39cf08b00 (diff)
downloadffmpeg-0cfd3d6dd6afe5b6db35f4bba93d3de3b400c046.tar.gz
avcodec/wmavoice: Fix rounding and integer anomalies in calc_input_response()
Fixes: out of array access Fixes: inf is outside the range of representable values of type 'int' Fixes: signed integer overflow: -9223372036854775808 - 1 cannot be represented in type 'long' Fixes: 19316/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_WMAVOICE_fuzzer-5677369365102592 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> (cherry picked from commit 38d37584448731f90977132b838d50ff1a28811b) Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
-rw-r--r--libavcodec/wmavoice.c6
1 files changed, 4 insertions, 2 deletions
diff --git a/libavcodec/wmavoice.c b/libavcodec/wmavoice.c
index db1ea3fa1e..927d9c9b56 100644
--- a/libavcodec/wmavoice.c
+++ b/libavcodec/wmavoice.c
@@ -636,12 +636,14 @@ static void calc_input_response(WMAVoiceContext *s, float *lpcs,
for (n = 0; n <= 64; n++) {
float pwr;
- idx = FFMAX(0, lrint((max - lpcs[n]) * irange) - 1);
+ idx = lrint((max - lpcs[n]) * irange - 1);
+ idx = FFMAX(0, idx);
pwr = wmavoice_denoise_power_table[s->denoise_strength][idx];
lpcs[n] = angle_mul * pwr;
/* 70.57 =~ 1/log10(1.0331663) */
- idx = (pwr * gain_mul - 0.0295) * 70.570526123;
+ idx = av_clipf((pwr * gain_mul - 0.0295) * 70.570526123, 0, INT_MAX / 2);
+
if (idx > 127) { // fall back if index falls outside table range
coeffs[n] = wmavoice_energy_table[127] *
powf(1.0331663, idx - 127);