summaryrefslogtreecommitdiff
path: root/libavcodec/wmv2dsp.c
diff options
context:
space:
mode:
authorMichael Niedermayer <michael@niedermayer.cc>2017-05-07 23:07:42 +0200
committerMichael Niedermayer <michael@niedermayer.cc>2017-05-08 03:25:17 +0200
commit8b1f66cf5c2e4d29ae06cdf3f12cdd3d808006bd (patch)
tree48c07a797da9a18addcf1d3c48bf80a054c5c593 /libavcodec/wmv2dsp.c
parent3c3d4ce4fda1428f9b9fe05dbc9a201a8f10c1fb (diff)
avcodec/wmv2dsp: Fix runtime error: signed integer overflow: 181 * -12156865 cannot be represented in type 'int'
Fixes: 1401/clusterfuzz-testcase-minimized-6526248148795392 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
Diffstat (limited to 'libavcodec/wmv2dsp.c')
-rw-r--r--libavcodec/wmv2dsp.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/libavcodec/wmv2dsp.c b/libavcodec/wmv2dsp.c
index 162ac92a72..7a3a851861 100644
--- a/libavcodec/wmv2dsp.c
+++ b/libavcodec/wmv2dsp.c
@@ -78,8 +78,8 @@ static void wmv2_idct_col(short * b)
a4 = (W0 * b[8 * 0] - W0 * b[8 * 4] ) >> 3;
/* step 2 */
- s1 = (181 * (a1 - a5 + a7 - a3) + 128) >> 8;
- s2 = (181 * (a1 - a5 - a7 + a3) + 128) >> 8;
+ s1 = (int)(181U * (a1 - a5 + a7 - a3) + 128) >> 8;
+ s2 = (int)(181U * (a1 - a5 - a7 + a3) + 128) >> 8;
/* step 3 */
b[8 * 0] = (a0 + a2 + a1 + a5 + (1 << 13)) >> 14;