aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michaelni@gmx.at>2014-10-28 01:23:40 +0100
committerMichael Niedermayer <michaelni@gmx.at>2014-11-01 15:40:38 +0100
commit81e1b5f5fe5b1200bd6baf48769999f6631af590 (patch)
tree395d5bd2a7a6a7c58b9df6f7e2008fa73fabdd49
parent6505eb45bcf450473e606d0d233d7480d5071da6 (diff)
downloadffmpeg-81e1b5f5fe5b1200bd6baf48769999f6631af590.tar.gz
avcodec/diracdec: Tighter checks on CODEBLOCKS_X/Y
Fixes very long but finite loop Fixes: asan_heap-oob_107866c_42_041.drc Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind Signed-off-by: Michael Niedermayer <michaelni@gmx.at> (cherry picked from commit 5145d22b88b9835db81c4d286b931a78e08ab76a) Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
-rw-r--r--libavcodec/diracdec.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/libavcodec/diracdec.c b/libavcodec/diracdec.c
index c4e9751c03..5579dfb2a4 100644
--- a/libavcodec/diracdec.c
+++ b/libavcodec/diracdec.c
@@ -1002,8 +1002,8 @@ static int dirac_unpack_idwt_params(DiracContext *s)
/* Codeblock parameters (core syntax only) */
if (get_bits1(gb)) {
for (i = 0; i <= s->wavelet_depth; i++) {
- CHECKEDREAD(s->codeblock[i].width , tmp < 1, "codeblock width invalid\n")
- CHECKEDREAD(s->codeblock[i].height, tmp < 1, "codeblock height invalid\n")
+ CHECKEDREAD(s->codeblock[i].width , tmp < 1 || tmp > (s->avctx->width >>s->wavelet_depth-i), "codeblock width invalid\n")
+ CHECKEDREAD(s->codeblock[i].height, tmp < 1 || tmp > (s->avctx->height>>s->wavelet_depth-i), "codeblock height invalid\n")
}
CHECKEDREAD(s->codeblock_mode, tmp > 1, "unknown codeblock mode\n")