mirror of https://git.ffmpeg.org/ffmpeg.git
avcodec/mscc & mwsc: Check loop counts before use
This could cause timeouts
Fixes: CID1439568 Untrusted loop bound
Sponsored-by: Sovereign Tech Fund
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit e35fe3d8b9
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
parent
25826459d9
commit
5cca477c51
|
@ -52,6 +52,9 @@ static int rle_uncompress(AVCodecContext *avctx, GetByteContext *gb, PutByteCont
|
|||
unsigned run = bytestream2_get_byte(gb);
|
||||
|
||||
if (run) {
|
||||
if (bytestream2_get_bytes_left_p(pb) < run * s->bpp)
|
||||
return AVERROR_INVALIDDATA;
|
||||
|
||||
switch (avctx->bits_per_coded_sample) {
|
||||
case 8:
|
||||
fill = bytestream2_get_byte(gb);
|
||||
|
@ -100,6 +103,9 @@ static int rle_uncompress(AVCodecContext *avctx, GetByteContext *gb, PutByteCont
|
|||
|
||||
bytestream2_seek_p(pb, y * avctx->width * s->bpp + x * s->bpp, SEEK_SET);
|
||||
} else {
|
||||
if (bytestream2_get_bytes_left_p(pb) < copy * s->bpp)
|
||||
return AVERROR_INVALIDDATA;
|
||||
|
||||
for (j = 0; j < copy; j++) {
|
||||
switch (avctx->bits_per_coded_sample) {
|
||||
case 8:
|
||||
|
|
|
@ -50,6 +50,10 @@ static int rle_uncompress(GetByteContext *gb, PutByteContext *pb, GetByteContext
|
|||
|
||||
if (run == 0) {
|
||||
run = bytestream2_get_le32(gb);
|
||||
|
||||
if (bytestream2_tell_p(pb) + width - w < run)
|
||||
return AVERROR_INVALIDDATA;
|
||||
|
||||
for (int j = 0; j < run; j++, w++) {
|
||||
if (w == width) {
|
||||
w = 0;
|
||||
|
@ -61,6 +65,10 @@ static int rle_uncompress(GetByteContext *gb, PutByteContext *pb, GetByteContext
|
|||
int pos = bytestream2_tell_p(pb);
|
||||
|
||||
bytestream2_seek(gbp, pos, SEEK_SET);
|
||||
|
||||
if (pos + width - w < fill)
|
||||
return AVERROR_INVALIDDATA;
|
||||
|
||||
for (int j = 0; j < fill; j++, w++) {
|
||||
if (w == width) {
|
||||
w = 0;
|
||||
|
@ -72,6 +80,9 @@ static int rle_uncompress(GetByteContext *gb, PutByteContext *pb, GetByteContext
|
|||
|
||||
intra = 0;
|
||||
} else {
|
||||
if (bytestream2_tell_p(pb) + width - w < run)
|
||||
return AVERROR_INVALIDDATA;
|
||||
|
||||
for (int j = 0; j < run; j++, w++) {
|
||||
if (w == width) {
|
||||
w = 0;
|
||||
|
|
Loading…
Reference in New Issue