diff options
author | Luca Barbato <lu_zero@gentoo.org> | 2013-06-09 18:27:05 +0200 |
---|---|---|
committer | Reinhard Tartler <siretart@tauware.de> | 2013-06-30 16:03:27 +0200 |
commit | c7934c6c0b0c6e33a83ed12f6e20dc977a945384 (patch) | |
tree | 9813d4bd577bf9fcec46cc901e0621c28cc28011 /libavcodec/4xm.c | |
parent | 04c29196ad70af4efe656a777cfbf6a02404303c (diff) | |
download | ffmpeg-c7934c6c0b0c6e33a83ed12f6e20dc977a945384.tar.gz |
4xm: do not overread the source buffer in decode_p_block
Check for out of picture macroblocks before calling mcdc.
Reported-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
CC: libav-stable@libav.org
(cherry picked from commit 94aefb1932be882fd93f66cf790ceb19ff575c19)
Signed-off-by: Reinhard Tartler <siretart@tauware.de>
Diffstat (limited to 'libavcodec/4xm.c')
-rw-r--r-- | libavcodec/4xm.c | 8 |
1 files changed, 8 insertions, 0 deletions
diff --git a/libavcodec/4xm.c b/libavcodec/4xm.c index cf9ad72522..99e0e2e4da 100644 --- a/libavcodec/4xm.c +++ b/libavcodec/4xm.c @@ -372,6 +372,10 @@ static int decode_p_block(FourXContext *f, uint16_t *dst, uint16_t *src, log2w, log2h, stride)) < 0) return ret; } else if (code == 3 && f->version < 2) { + if (start > src || src > end) { + av_log(f->avctx, AV_LOG_ERROR, "mv out of pic\n"); + return AVERROR_INVALIDDATA; + } mcdc(dst, src, log2w, h, stride, 1, 0); } else if (code == 4) { src += f->mv[bytestream2_get_byte(&f->g)]; @@ -381,6 +385,10 @@ static int decode_p_block(FourXContext *f, uint16_t *dst, uint16_t *src, } mcdc(dst, src, log2w, h, stride, 1, bytestream2_get_le16(&f->g2)); } else if (code == 5) { + if (start > src || src > end) { + av_log(f->avctx, AV_LOG_ERROR, "mv out of pic\n"); + return AVERROR_INVALIDDATA; + } mcdc(dst, src, log2w, h, stride, 0, bytestream2_get_le16(&f->g2)); } else if (code == 6) { if (log2w) { |