aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michael@niedermayer.cc>2017-04-19 22:58:27 +0200
committerMichael Niedermayer <michael@niedermayer.cc>2017-04-19 23:52:20 +0200
commit164758a831b13c8a0fa1ba7d84e53dffcea2904a (patch)
tree031b9c253491841f80c3e8e448dd5b27e6ee2e89
parentc6aaf0840cf9b2b8cb139ed7110d3d47c2bf3d12 (diff)
downloadffmpeg-164758a831b13c8a0fa1ba7d84e53dffcea2904a.tar.gz
tools/target_dec_fuzzer: Fuzz video decoder related fields in context.
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
-rw-r--r--tools/target_dec_fuzzer.c13
1 files changed, 13 insertions, 0 deletions
diff --git a/tools/target_dec_fuzzer.c b/tools/target_dec_fuzzer.c
index cb3bc50919..43442a3616 100644
--- a/tools/target_dec_fuzzer.c
+++ b/tools/target_dec_fuzzer.c
@@ -49,6 +49,7 @@
#include "libavutil/intreadwrite.h"
#include "libavcodec/avcodec.h"
+#include "libavcodec/bytestream.h"
#include "libavformat/avformat.h"
static void error(const char *err)
@@ -151,6 +152,18 @@ int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
ctx->max_pixels = 4096 * 4096; //To reduce false positive OOM and hangs
+ if (size > 1024) {
+ GetByteContext gbc;
+ bytestream2_init(&gbc, data + size - 1024, 1024);
+ ctx->width = bytestream2_get_le32(&gbc);
+ ctx->height = bytestream2_get_le32(&gbc);
+ ctx->bit_rate = bytestream2_get_le64(&gbc);
+ ctx->bits_per_coded_sample = bytestream2_get_le32(&gbc);
+ if (av_image_check_size(ctx->width, ctx->height, 0, ctx))
+ ctx->width = ctx->height = 0;
+ size -= 1024;
+ }
+
int res = avcodec_open2(ctx, c, NULL);
if (res < 0)
return res;