aboutsummaryrefslogtreecommitdiffstats
path: root/libavcodec/xan.c
diff options
context:
space:
mode:
authorLuca Barbato <lu_zero@gentoo.org>2014-08-08 18:07:43 +0200
committerLuca Barbato <lu_zero@gentoo.org>2014-08-09 04:01:15 +0200
commit0ab76ddf313eeab70d06619ae0376fd7dd40761b (patch)
tree5b9cc612dea64c831a020c831ddd998c709cb796 /libavcodec/xan.c
parent042c25f54bd25b52d2936b822be026450971a82d (diff)
downloadffmpeg-0ab76ddf313eeab70d06619ae0376fd7dd40761b.tar.gz
avcodec: Introduce ff_get_buffer
Validate the image size there as is done in the other release branches. Bug-Id: CVE-2011-3935 Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Diffstat (limited to 'libavcodec/xan.c')
-rw-r--r--libavcodec/xan.c3
1 files changed, 2 insertions, 1 deletions
diff --git a/libavcodec/xan.c b/libavcodec/xan.c
index d0def65f20..fd7de1c9d7 100644
--- a/libavcodec/xan.c
+++ b/libavcodec/xan.c
@@ -34,6 +34,7 @@
#include "libavutil/intreadwrite.h"
#include "avcodec.h"
+#include "internal.h"
#include "bytestream.h"
#define BITSTREAM_READER_LE
#include "get_bits.h"
@@ -560,7 +561,7 @@ static int xan_decode_frame(AVCodecContext *avctx,
return AVERROR_INVALIDDATA;
}
- if ((ret = avctx->get_buffer(avctx, &s->current_frame))) {
+ if ((ret = ff_get_buffer(avctx, &s->current_frame))) {
av_log(s->avctx, AV_LOG_ERROR, "get_buffer() failed\n");
return ret;
}