From 8a03a60b4af46c001d5686b9303f48f6c4ebdf6c Mon Sep 17 00:00:00 2001 From: Michael Niedermayer Date: Sun, 18 Nov 2012 21:36:06 +0100 Subject: [PATCH] h264: Check gray scale CBP, fix out of array accesses. Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind Signed-off-by: Michael Niedermayer --- libavcodec/h264_cabac.c | 5 +++++ libavcodec/h264_cavlc.c | 5 +++++ 2 files changed, 10 insertions(+) diff --git a/libavcodec/h264_cabac.c b/libavcodec/h264_cabac.c index a37094b3f5..76a648143d 100644 --- a/libavcodec/h264_cabac.c +++ b/libavcodec/h264_cabac.c @@ -2266,6 +2266,11 @@ decode_intra_mb: cbp = decode_cabac_mb_cbp_luma( h ); if(decode_chroma) cbp |= decode_cabac_mb_cbp_chroma( h ) << 4; + } else { + if (!decode_chroma && cbp>15) { + av_log(s->avctx, AV_LOG_ERROR, "gray chroma\n"); + return AVERROR_INVALIDDATA; + } } h->cbp_table[mb_xy] = h->cbp = cbp; diff --git a/libavcodec/h264_cavlc.c b/libavcodec/h264_cavlc.c index 6dfe2474cc..cd1130a4bc 100644 --- a/libavcodec/h264_cavlc.c +++ b/libavcodec/h264_cavlc.c @@ -1070,6 +1070,11 @@ decode_intra_mb: if(IS_INTRA4x4(mb_type)) cbp= golomb_to_intra4x4_cbp_gray[cbp]; else cbp= golomb_to_inter_cbp_gray[cbp]; } + } else { + if (!decode_chroma && cbp>15) { + av_log(s->avctx, AV_LOG_ERROR, "gray chroma\n"); + return AVERROR_INVALIDDATA; + } } if(dct8x8_allowed && (cbp&15) && !IS_INTRA(mb_type)){