Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Contribute to GitLab
Sign in / Register
Toggle navigation
F
ffmpeg.wasm-core
Project
Project
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
Linshizhi
ffmpeg.wasm-core
Commits
4fd56f84
Commit
4fd56f84
authored
Sep 29, 2011
by
Laurent Aimar
Committed by
Janne Grunau
Oct 07, 2011
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
quickdraw: Check for out of bound reads
Signed-off-by:
Janne Grunau
<
janne-libav@jannau.net
>
parent
e3ca9b93
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
12 additions
and
0 deletions
+12
-0
qdrw.c
libavcodec/qdrw.c
+12
-0
No files found.
libavcodec/qdrw.c
View file @
4fd56f84
...
...
@@ -37,6 +37,7 @@ static int decode_frame(AVCodecContext *avctx,
AVPacket
*
avpkt
)
{
const
uint8_t
*
buf
=
avpkt
->
data
;
const
uint8_t
*
buf_end
=
avpkt
->
data
+
avpkt
->
size
;
int
buf_size
=
avpkt
->
size
;
QdrawContext
*
const
a
=
avctx
->
priv_data
;
AVFrame
*
const
p
=
(
AVFrame
*
)
&
a
->
pic
;
...
...
@@ -59,6 +60,8 @@ static int decode_frame(AVCodecContext *avctx,
outdata
=
a
->
pic
.
data
[
0
];
if
(
buf_end
-
buf
<
0x68
+
4
)
return
AVERROR_INVALIDDATA
;
buf
+=
0x68
;
/* jump to palette */
colors
=
AV_RB32
(
buf
);
buf
+=
4
;
...
...
@@ -67,6 +70,8 @@ static int decode_frame(AVCodecContext *avctx,
av_log
(
avctx
,
AV_LOG_ERROR
,
"Error color count - %i(0x%X)
\n
"
,
colors
,
colors
);
return
-
1
;
}
if
(
buf_end
-
buf
<
(
colors
+
1
)
*
8
)
return
AVERROR_INVALIDDATA
;
pal
=
(
uint32_t
*
)
p
->
data
[
1
];
for
(
i
=
0
;
i
<=
colors
;
i
++
)
{
...
...
@@ -89,6 +94,8 @@ static int decode_frame(AVCodecContext *avctx,
}
p
->
palette_has_changed
=
1
;
if
(
buf_end
-
buf
<
18
)
return
AVERROR_INVALIDDATA
;
buf
+=
18
;
/* skip unneeded data */
for
(
i
=
0
;
i
<
avctx
->
height
;
i
++
)
{
int
size
,
left
,
code
,
pix
;
...
...
@@ -100,6 +107,9 @@ static int decode_frame(AVCodecContext *avctx,
out
=
outdata
;
size
=
AV_RB16
(
buf
);
/* size of packed line */
buf
+=
2
;
if
(
buf_end
-
buf
<
size
)
return
AVERROR_INVALIDDATA
;
left
=
size
;
next
=
buf
+
size
;
while
(
left
>
0
)
{
...
...
@@ -115,6 +125,8 @@ static int decode_frame(AVCodecContext *avctx,
}
else
{
/* copy */
if
((
out
+
code
)
>
(
outdata
+
a
->
pic
.
linesize
[
0
]))
break
;
if
(
buf_end
-
buf
<
code
+
1
)
return
AVERROR_INVALIDDATA
;
memcpy
(
out
,
buf
,
code
+
1
);
out
+=
code
+
1
;
buf
+=
code
+
1
;
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment