mirror of https://git.ffmpeg.org/ffmpeg.git
smc: fix the bounds check
Fixes invalid writes when there are more blocks in a run than total
remaining blocks.
CC: libav-stable@libav.org
Bug-ID: CVE-2014-8548
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: Anton Khirnov <anton@khirnov.net>
(cherry picked from commit d423dd72be
)
Signed-off-by: Anton Khirnov <anton@khirnov.net>
This commit is contained in:
parent
eac49477aa
commit
58dc526ebf
|
@ -70,7 +70,7 @@ typedef struct SmcContext {
|
|||
row_ptr += stride * 4; \
|
||||
} \
|
||||
total_blocks--; \
|
||||
if (total_blocks < 0) \
|
||||
if (total_blocks < !!n_blocks) \
|
||||
{ \
|
||||
av_log(s->avctx, AV_LOG_INFO, "warning: block counter just went negative (this should not happen)\n"); \
|
||||
return; \
|
||||
|
|
Loading…
Reference in New Issue