aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMichael Niedermayer <michaelni@gmx.at>2014-08-06 18:19:57 +0100
committerAnton Khirnov <anton@khirnov.net>2014-08-06 19:29:48 +0000
commitc79cf0129edafc388ba1c47cd7b6a620557e48de (patch)
tree5870a9f6c10c68bb4cc60645d28fb14817eaef85
parent9d5f4f025304ac7c69775179044e6f69f370441a (diff)
downloadffmpeg-c79cf0129edafc388ba1c47cd7b6a620557e48de.tar.gz
error_concealment: avoid using the picture if not fully setup
Fixes state becoming inconsistent and a null pointer dereference. CC: libav-stable@libav.org Bug-Id: CVE-2013-0860 Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind Signed-off-by: Vittorio Giovara <vittorio.giovara@gmail.com> Signed-off-by: Anton Khirnov <anton@khirnov.net>
-rw-r--r--libavcodec/error_resilience.c6
1 files changed, 6 insertions, 0 deletions
diff --git a/libavcodec/error_resilience.c b/libavcodec/error_resilience.c
index 96f49c8adb..2735c6667d 100644
--- a/libavcodec/error_resilience.c
+++ b/libavcodec/error_resilience.c
@@ -900,6 +900,12 @@ void ff_er_frame_end(MpegEncContext *s)
return;
};
+ if (s->picture_structure == PICT_FRAME &&
+ s->current_picture.f.linesize[0] != s->current_picture_ptr->f.linesize[0]) {
+ av_log(s->avctx, AV_LOG_ERROR, "Error concealment not possible, frame not fully initialized\n");
+ return;
+ }
+
if (s->current_picture.f.motion_val[0] == NULL) {
av_log(s->avctx, AV_LOG_ERROR, "Warning MVs not available\n");