summaryrefslogtreecommitdiff
path: root/libavcodec/bfi.c
diff options
context:
space:
mode:
authorDaniel Kang <daniel.d.kang@gmail.com>2011-01-06 23:14:27 +0000
committerCarl Eugen Hoyos <cehoyos@rainbow.studorg.tuwien.ac.at>2011-01-06 23:14:27 +0000
commit65cd45a88c4a657b4ae0c81b753bb0d065a4e25a (patch)
tree1dae0443bcf3177eb01289e808b11b65a7f4211e /libavcodec/bfi.c
parentf5a2d285f94585e6336838fb1efc9c28cad93142 (diff)
Prevent a crash by sanity checking buffer reads.
Patch by Daniel Kang, daniel.d.kang at gmail Originally committed as revision 26251 to svn://svn.ffmpeg.org/ffmpeg/trunk
Diffstat (limited to 'libavcodec/bfi.c')
-rw-r--r--libavcodec/bfi.c11
1 files changed, 10 insertions, 1 deletions
diff --git a/libavcodec/bfi.c b/libavcodec/bfi.c
index 91c8f6d24d..ca72c1fd46 100644
--- a/libavcodec/bfi.c
+++ b/libavcodec/bfi.c
@@ -47,7 +47,7 @@ static av_cold int bfi_decode_init(AVCodecContext * avctx)
static int bfi_decode_frame(AVCodecContext * avctx, void *data,
int *data_size, AVPacket *avpkt)
{
- const uint8_t *buf = avpkt->data;
+ const uint8_t *buf = avpkt->data, *buf_end = avpkt->data + avpkt->size;
int buf_size = avpkt->size;
BFIContext *bfi = avctx->priv_data;
uint8_t *dst = bfi->dst;
@@ -99,6 +99,11 @@ static int bfi_decode_frame(AVCodecContext * avctx, void *data,
unsigned int code = byte >> 6;
unsigned int length = byte & ~0xC0;
+ if (buf >= buf_end) {
+ av_log(avctx, AV_LOG_ERROR, "Input resolution larger than actual frame.\n");
+ return -1;
+ }
+
/* Get length and offset(if required) */
if (length == 0) {
if (code == 1) {
@@ -121,6 +126,10 @@ static int bfi_decode_frame(AVCodecContext * avctx, void *data,
switch (code) {
case 0: //Normal Chain
+ if (length >= buf_end - buf) {
+ av_log(avctx, AV_LOG_ERROR, "Frame larger than buffer.\n");
+ return -1;
+ }
bytestream_get_buffer(&buf, dst, length);
dst += length;
break;