summaryrefslogtreecommitdiff
path: root/libavcodec/vc1.c
diff options
context:
space:
mode:
authorMichael Niedermayer <michaelni@gmx.at>2012-11-16 00:48:15 +0100
committerMartin Storsjö <martin@martin.st>2013-05-15 12:13:53 +0300
commit4162fc62b30d5b57910c17e46f2a9319a09cdae0 (patch)
treee0b1e986b98ed70474759a188d3633a0bac50c79 /libavcodec/vc1.c
parentec7d002e55590bf9e2c2745065ec3463364a5273 (diff)
vc1dec: Do not allow field_mode to change after the first header
This fixes out of array accesses. Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind Signed-off-by: Martin Storsjö <martin@martin.st>
Diffstat (limited to 'libavcodec/vc1.c')
-rw-r--r--libavcodec/vc1.c17
1 files changed, 11 insertions, 6 deletions
diff --git a/libavcodec/vc1.c b/libavcodec/vc1.c
index 25e3579d5c..86651fecd8 100644
--- a/libavcodec/vc1.c
+++ b/libavcodec/vc1.c
@@ -825,6 +825,7 @@ int ff_vc1_parse_frame_header_adv(VC1Context *v, GetBitContext* gb)
int status;
int mbmodetab, imvtab, icbptab, twomvbptab, fourmvbptab; /* useful only for debugging */
int scale, shift, i; /* for initializing LUT for intensity compensation */
+ int field_mode, fcm;
v->p_frame_skipped = 0;
if (v->second_field) {
@@ -836,19 +837,23 @@ int ff_vc1_parse_frame_header_adv(VC1Context *v, GetBitContext* gb)
goto parse_common_info;
}
- v->field_mode = 0;
+ field_mode = 0;
if (v->interlace) {
- v->fcm = decode012(gb);
- if (v->fcm) {
- if (v->fcm == ILACE_FIELD)
- v->field_mode = 1;
+ fcm = decode012(gb);
+ if (fcm) {
+ if (fcm == ILACE_FIELD)
+ field_mode = 1;
if (!v->warn_interlaced++)
av_log(v->s.avctx, AV_LOG_ERROR,
"Interlaced frames/fields support is incomplete\n");
}
} else {
- v->fcm = PROGRESSIVE;
+ fcm = PROGRESSIVE;
}
+ if (!v->first_pic_header_flag && v->field_mode != field_mode)
+ return AVERROR_INVALIDDATA;
+ v->field_mode = field_mode;
+ v->fcm = fcm;
if (v->field_mode) {
v->fptype = get_bits(gb, 3);