aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michaelni@gmx.at>2015-05-13 13:21:52 +0200
committerMichael Niedermayer <michaelni@gmx.at>2015-06-17 21:50:07 +0200
commit87d2c6105df2c1b37c4b3b1b83ab4f65734ade2c (patch)
tree67deda7ae75edb4e0240f79752cda86950d7add7
parenteed8ccd9eb3eb37e7ba09c5fb921f7db76d305ae (diff)
downloadffmpeg-87d2c6105df2c1b37c4b3b1b83ab4f65734ade2c.tar.gz
avcodec/hevc: Check num_entry_point_offsets
Fixes CID1239099 part 2 Signed-off-by: Michael Niedermayer <michaelni@gmx.at> (cherry picked from commit 1c6ae98d4a9ff9ea607df87908393eda4ebdf4e8) Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
-rw-r--r--libavcodec/hevc.c9
1 files changed, 8 insertions, 1 deletions
diff --git a/libavcodec/hevc.c b/libavcodec/hevc.c
index 7b2bd154f3..9d8204cf23 100644
--- a/libavcodec/hevc.c
+++ b/libavcodec/hevc.c
@@ -644,7 +644,14 @@ static int hls_slice_header(HEVCContext *s)
sh->num_entry_point_offsets = 0;
if (s->pps->tiles_enabled_flag || s->pps->entropy_coding_sync_enabled_flag) {
- sh->num_entry_point_offsets = get_ue_golomb_long(gb);
+ unsigned num_entry_point_offsets = get_ue_golomb_long(gb);
+ // It would be possible to bound this tighter but this here is simpler
+ if (sh->num_entry_point_offsets > get_bits_left(gb)) {
+ av_log(s->avctx, AV_LOG_ERROR, "num_entry_point_offsets %d is invalid\n", num_entry_point_offsets);
+ return AVERROR_INVALIDDATA;
+ }
+
+ sh->num_entry_point_offsets = num_entry_point_offsets;
if (sh->num_entry_point_offsets > 0) {
int offset_len = get_ue_golomb_long(gb) + 1;
int segments = offset_len >> 4;