summaryrefslogtreecommitdiff
path: root/libavcodec/tiff.c
diff options
context:
space:
mode:
authorAlex Converse <alex.converse@gmail.com>2012-02-23 10:47:50 -0800
committerAlex Converse <alex.converse@gmail.com>2012-02-23 16:23:51 -0800
commit447363870f2f91e125e07ac2d0820359a5d86b06 (patch)
treef74878afd1c424e9858cb00831764a2091937d55 /libavcodec/tiff.c
parente32548d1331ce05a054f1028fcdda8823a4f215a (diff)
tiff: Prevent overreads in the type_sizes array.
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind CC: libav-stable@libav.org
Diffstat (limited to 'libavcodec/tiff.c')
-rw-r--r--libavcodec/tiff.c15
1 files changed, 11 insertions, 4 deletions
diff --git a/libavcodec/tiff.c b/libavcodec/tiff.c
index 51ebd69f66..d807149922 100644
--- a/libavcodec/tiff.c
+++ b/libavcodec/tiff.c
@@ -289,6 +289,11 @@ static int tiff_decode_tag(TiffContext *s, const uint8_t *start, const uint8_t *
count = tget_long(&buf, s->le);
off = tget_long(&buf, s->le);
+ if (type == 0 || type >= FF_ARRAY_ELEMS(type_sizes)) {
+ av_log(s->avctx, AV_LOG_DEBUG, "Unknown tiff type (%u) encountered\n", type);
+ return 0;
+ }
+
if(count == 1){
switch(type){
case TIFF_BYTE:
@@ -310,10 +315,12 @@ static int tiff_decode_tag(TiffContext *s, const uint8_t *start, const uint8_t *
value = UINT_MAX;
buf = start + off;
}
- }else if(type_sizes[type] * count <= 4){
- buf -= 4;
- }else{
- buf = start + off;
+ } else {
+ if (count <= 4 && type_sizes[type] * count <= 4) {
+ buf -= 4;
+ } else {
+ buf = start + off;
+ }
}
if(buf && (buf < start || buf > end_buf)){