summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMichael Niedermayer <michael@niedermayer.cc>2019-09-10 20:20:31 +0200
committerMichael Niedermayer <michael@niedermayer.cc>2019-09-28 18:34:53 +0200
commite75e7fe1601b97c31e3ce90473ab71b9a0667573 (patch)
treef16d9a7f44abfb94043a1f4c984cb00c0423227a
parentced9a1cd0ab76a65e509b0d7c56965d61ea1df84 (diff)
vcodec/vc1: compute rangex/y only for P/B frames
Fixes: left shift of 1073741824 by 1 places cannot be represented in type 'int' Fixes: 16976/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_VC1_fuzzer-4847262047404032 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
-rw-r--r--libavcodec/vc1.c9
1 files changed, 5 insertions, 4 deletions
diff --git a/libavcodec/vc1.c b/libavcodec/vc1.c
index 13119bd0b3..9df778bcab 100644
--- a/libavcodec/vc1.c
+++ b/libavcodec/vc1.c
@@ -1319,16 +1319,17 @@ int ff_vc1_parse_frame_header_adv(VC1Context *v, GetBitContext* gb)
break;
}
- if (v->fcm != PROGRESSIVE && !v->s.quarter_sample) {
- v->range_x <<= 1;
- v->range_y <<= 1;
- }
/* AC Syntax */
v->c_ac_table_index = decode012(gb);
if (v->s.pict_type == AV_PICTURE_TYPE_I || v->s.pict_type == AV_PICTURE_TYPE_BI) {
v->y_ac_table_index = decode012(gb);
}
+ else if (v->fcm != PROGRESSIVE && !v->s.quarter_sample) {
+ v->range_x <<= 1;
+ v->range_y <<= 1;
+ }
+
/* DC Syntax */
v->s.dc_table_index = get_bits1(gb);
if ((v->s.pict_type == AV_PICTURE_TYPE_I || v->s.pict_type == AV_PICTURE_TYPE_BI)