[FFmpeg-cvslog] dfa: check for invalid access in decode_wdlt().
    Anton Khirnov 
    git at videolan.org
       
    Thu Apr  4 13:47:27 CEST 2013
    
    
  
ffmpeg | branch: master | Anton Khirnov <anton at khirnov.net> | Wed Mar 27 18:18:38 2013 +0100| [3623589edc7b1257bb45aa9e52c9631e133f22b6] | committer: Anton Khirnov
dfa: check for invalid access in decode_wdlt().
This can happen when the number of skipped lines is not consistent with
the number of coded lines.
Reported-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
CC: libav-stable at libav.org
> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=3623589edc7b1257bb45aa9e52c9631e133f22b6
---
 libavcodec/dfa.c |    2 ++
 1 file changed, 2 insertions(+)
diff --git a/libavcodec/dfa.c b/libavcodec/dfa.c
index bbe4ce2..6619b98 100644
--- a/libavcodec/dfa.c
+++ b/libavcodec/dfa.c
@@ -255,6 +255,8 @@ static int decode_wdlt(GetByteContext *gb, uint8_t *frame, int width, int height
             segments = bytestream2_get_le16(gb);
         }
         line_ptr = frame;
+        if (frame_end - frame < width)
+            return AVERROR_INVALIDDATA;
         frame += width;
         y++;
         while (segments--) {
    
    
More information about the ffmpeg-cvslog
mailing list