mirror of
https://git.ffmpeg.org/ffmpeg.git
synced 2025-02-25 08:10:41 +00:00
interplayacm: check for too large b
This fixes out-of-bounds reads.
Reviewed-by: Paul B Mahol <onemda@gmail.com>
Signed-off-by: Andreas Cadhalpun <Andreas.Cadhalpun@googlemail.com>
(cherry picked from commit 14e4e26559
)
Signed-off-by: Andreas Cadhalpun <Andreas.Cadhalpun@googlemail.com>
This commit is contained in:
parent
346fa70bb8
commit
c90d521f16
@ -326,6 +326,10 @@ static int t15(InterplayACMContext *s, unsigned ind, unsigned col)
|
|||||||
for (i = 0; i < s->rows; i++) {
|
for (i = 0; i < s->rows; i++) {
|
||||||
/* b = (x1) + (x2 * 3) + (x3 * 9) */
|
/* b = (x1) + (x2 * 3) + (x3 * 9) */
|
||||||
b = get_bits(gb, 5);
|
b = get_bits(gb, 5);
|
||||||
|
if (b > 26) {
|
||||||
|
av_log(NULL, AV_LOG_ERROR, "Too large b = %d > 26\n", b);
|
||||||
|
return AVERROR_INVALIDDATA;
|
||||||
|
}
|
||||||
|
|
||||||
n1 = (mul_3x3[b] & 0x0F) - 1;
|
n1 = (mul_3x3[b] & 0x0F) - 1;
|
||||||
n2 = ((mul_3x3[b] >> 4) & 0x0F) - 1;
|
n2 = ((mul_3x3[b] >> 4) & 0x0F) - 1;
|
||||||
@ -351,6 +355,10 @@ static int t27(InterplayACMContext *s, unsigned ind, unsigned col)
|
|||||||
for (i = 0; i < s->rows; i++) {
|
for (i = 0; i < s->rows; i++) {
|
||||||
/* b = (x1) + (x2 * 5) + (x3 * 25) */
|
/* b = (x1) + (x2 * 5) + (x3 * 25) */
|
||||||
b = get_bits(gb, 7);
|
b = get_bits(gb, 7);
|
||||||
|
if (b > 124) {
|
||||||
|
av_log(NULL, AV_LOG_ERROR, "Too large b = %d > 124\n", b);
|
||||||
|
return AVERROR_INVALIDDATA;
|
||||||
|
}
|
||||||
|
|
||||||
n1 = (mul_3x5[b] & 0x0F) - 2;
|
n1 = (mul_3x5[b] & 0x0F) - 2;
|
||||||
n2 = ((mul_3x5[b] >> 4) & 0x0F) - 2;
|
n2 = ((mul_3x5[b] >> 4) & 0x0F) - 2;
|
||||||
@ -375,6 +383,10 @@ static int t37(InterplayACMContext *s, unsigned ind, unsigned col)
|
|||||||
for (i = 0; i < s->rows; i++) {
|
for (i = 0; i < s->rows; i++) {
|
||||||
/* b = (x1) + (x2 * 11) */
|
/* b = (x1) + (x2 * 11) */
|
||||||
b = get_bits(gb, 7);
|
b = get_bits(gb, 7);
|
||||||
|
if (b > 120) {
|
||||||
|
av_log(NULL, AV_LOG_ERROR, "Too large b = %d > 120\n", b);
|
||||||
|
return AVERROR_INVALIDDATA;
|
||||||
|
}
|
||||||
|
|
||||||
n1 = (mul_2x11[b] & 0x0F) - 5;
|
n1 = (mul_2x11[b] & 0x0F) - 5;
|
||||||
n2 = ((mul_2x11[b] >> 4) & 0x0F) - 5;
|
n2 = ((mul_2x11[b] >> 4) & 0x0F) - 5;
|
||||||
|
Loading…
Reference in New Issue
Block a user