diff options
author | Michael Niedermayer <michael@niedermayer.cc> | 2019-06-16 11:39:15 +0200 |
---|---|---|
committer | Michael Niedermayer <michael@niedermayer.cc> | 2019-12-02 19:41:48 +0100 |
commit | f9749f3335f88890594fd357b895c6c5a9b166d2 (patch) | |
tree | d8f55277bb232daa5a05f12a8fe5354e5adb3fc6 /libavutil/tea.h | |
parent | f2eb30e65469ab08b1e897e5872c040a6a174f15 (diff) | |
download | ffmpeg-f9749f3335f88890594fd357b895c6c5a9b166d2.tar.gz |
avcodec/apedec: Fix multiple integer overflows and undefined behaviorin filter_3800()
Fixes: left shift of negative value -4
Fixes: signed integer overflow: -15091694 * 167 cannot be represented in type 'int'
Fixes: signed integer overflow: 1898547155 + 453967445 cannot be represented in type 'int'
Fixes: 15258/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_APE_fuzzer-5759095564402688
Fixes: signed integer overflow: 962196438 * 31 cannot be represented in type 'int'
Fixes: 15364/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_APE_fuzzer-5718799845687296
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 267eb2ab7f87696e1a156ca9a5ff1b1628d170c1)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
Diffstat (limited to 'libavutil/tea.h')
0 files changed, 0 insertions, 0 deletions