From 17e66c9ff4774e254932d34dade77b1c04139a4f Mon Sep 17 00:00:00 2001 From: Michael Niedermayer Date: Wed, 22 May 2013 03:17:35 +0200 Subject: [PATCH] j2k & jpeg2000dec: reset numX/Ytiles if tiles failed allocation Fixes null pointer dereference Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind Signed-off-by: Michael Niedermayer --- libavcodec/j2kdec.c | 2 ++ libavcodec/jpeg2000dec.c | 2 ++ 2 files changed, 4 insertions(+) diff --git a/libavcodec/j2kdec.c b/libavcodec/j2kdec.c index 22bbb2effd..a02b84b820 100644 --- a/libavcodec/j2kdec.c +++ b/libavcodec/j2kdec.c @@ -957,6 +957,8 @@ static int decode_codestream(Jpeg2000DecoderContext *s) switch (marker){ case JPEG2000_SIZ: ret = get_siz(s); + if (!s->tile) + s->numXtiles = s->numYtiles = 0; break; case JPEG2000_COC: ret = get_coc(s, codsty, properties); diff --git a/libavcodec/jpeg2000dec.c b/libavcodec/jpeg2000dec.c index a43cc7e7c6..0735da12f0 100644 --- a/libavcodec/jpeg2000dec.c +++ b/libavcodec/jpeg2000dec.c @@ -1181,6 +1181,8 @@ static int jpeg2000_read_main_headers(Jpeg2000DecoderContext *s) switch (marker) { case JPEG2000_SIZ: ret = get_siz(s); + if (!s->tile) + s->numXtiles = s->numYtiles = 0; break; case JPEG2000_COC: ret = get_coc(s, codsty, properties);