aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michael@niedermayer.cc>2017-05-16 03:04:26 +0200
committerMichael Niedermayer <michael@niedermayer.cc>2017-06-02 01:14:38 +0200
commit72e5ccfe3783db37131de3ec4606ba512f98cd97 (patch)
tree9cfff80f7d667858a5f8ecb36ac2f4df3019ef4d
parentb147ded288ead7b4f22de4add3b8912ae54b406f (diff)
downloadffmpeg-72e5ccfe3783db37131de3ec4606ba512f98cd97.tar.gz
avcodec/truemotion1: Fix multiple runtime error: signed integer overflow: 1246906962 * 2 cannot be represented in type 'int'
Fixes: 1616/clusterfuzz-testcase-minimized-5119196578971648 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> (cherry picked from commit 5ea6bc2a166edac37042f2bbc28eb603a0fbeccb) Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
-rw-r--r--libavcodec/truemotion1.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/libavcodec/truemotion1.c b/libavcodec/truemotion1.c
index 57694cb892..e1824384c5 100644
--- a/libavcodec/truemotion1.c
+++ b/libavcodec/truemotion1.c
@@ -180,7 +180,7 @@ static int make_ydt15_entry(int p1, int p2, int16_t *ydt)
lo += (lo * 32) + (lo * 1024);
hi = ydt[p2];
hi += (hi * 32) + (hi * 1024);
- return (lo + (hi * (1 << 16))) * 2;
+ return (lo + (hi * (1U << 16))) * 2;
}
static int make_cdt15_entry(int p1, int p2, int16_t *cdt)
@@ -190,7 +190,7 @@ static int make_cdt15_entry(int p1, int p2, int16_t *cdt)
b = cdt[p2];
r = cdt[p1] * 1024;
lo = b + r;
- return (lo + (lo * (1 << 16))) * 2;
+ return (lo + (lo * (1U << 16))) * 2;
}
#if HAVE_BIGENDIAN