diff options
author | Michael Niedermayer <michael@niedermayer.cc> | 2021-01-20 00:00:27 +0100 |
---|---|---|
committer | Michael Niedermayer <michael@niedermayer.cc> | 2021-10-17 21:34:53 +0200 |
commit | e4bae4cb70835bd70c7d745a495e4e11e5cd2f44 (patch) | |
tree | 0a8068ef0a1ae3da8ba8185a5b0c1308cc1de1c9 | |
parent | c9c3db0799c86edb7f1313a6152c95bd0a7833e9 (diff) | |
download | ffmpeg-e4bae4cb70835bd70c7d745a495e4e11e5cd2f44.tar.gz |
avformat/asfdec_o: Check for EOF in asf_read_marker()
Fixes: Timeout
Fixes: 26460/clusterfuzz-testcase-minimized-ffmpeg_dem_ASF_O_fuzzer-5710884393189376
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 9e3d09f435f83f9653056b2fecc4d03ac45f3ffd)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
-rw-r--r-- | libavformat/asfdec_o.c | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/libavformat/asfdec_o.c b/libavformat/asfdec_o.c index f7d40e3b1e..4755fef5a7 100644 --- a/libavformat/asfdec_o.c +++ b/libavformat/asfdec_o.c @@ -246,6 +246,9 @@ static int asf_read_marker(AVFormatContext *s, const GUIDParseTable *g) avio_skip(pb, 4); // flags len = avio_rl32(pb); + if (avio_feof(pb)) + return AVERROR_INVALIDDATA; + if ((ret = avio_get_str16le(pb, len, name, sizeof(name))) < len) avio_skip(pb, len - ret); |