diff options
author | Thierry Foucu <tfoucu@gmail.com> | 2011-11-17 09:39:52 -0800 |
---|---|---|
committer | Reinhard Tartler <siretart@tauware.de> | 2011-12-04 09:21:09 +0100 |
commit | ba4b08b78918f399f9c9524750b26e904d146078 (patch) | |
tree | fbe91f770f9f007995fbd75dc4af8926fd012335 | |
parent | 67a7ed623b678a84c992dd7bf3e3d0329f83621b (diff) | |
download | ffmpeg-ba4b08b78918f399f9c9524750b26e904d146078.tar.gz |
vp6: Fix illegal read.
Found with Address Sanitizer
Signed-off-by: Alex Converse <alex.converse@gmail.com>
(cherry picked from commit e0966eb140b3569b3d6b5b5008961944ef229c06)
Signed-off-by: Reinhard Tartler <siretart@tauware.de>
-rw-r--r-- | libavcodec/vp6.c | 9 |
1 files changed, 6 insertions, 3 deletions
diff --git a/libavcodec/vp6.c b/libavcodec/vp6.c index ecfc81f048..02fe70bf7f 100644 --- a/libavcodec/vp6.c +++ b/libavcodec/vp6.c @@ -440,7 +440,8 @@ static void vp6_parse_coeff(VP56Context *s) model1 = model->coeff_dccv[pt]; model2 = model->coeff_dcct[pt][ctx]; - for (coeff_idx=0; coeff_idx<64; ) { + coeff_idx = 0; + for (;;) { if ((coeff_idx>1 && ct==0) || vp56_rac_get_prob(c, model2[0])) { /* parse a coeff */ if (vp56_rac_get_prob(c, model2[2])) { @@ -481,8 +482,10 @@ static void vp6_parse_coeff(VP56Context *s) run += vp56_rac_get_prob(c, model3[i+8]) << i; } } - - cg = vp6_coeff_groups[coeff_idx+=run]; + coeff_idx += run; + if (coeff_idx >= 64) + break; + cg = vp6_coeff_groups[coeff_idx]; model1 = model2 = model->coeff_ract[pt][ct][cg]; } |