Commit 5aba5b89 authored by Michael Niedermayer's avatar Michael Niedermayer

avcodec/mpeg4videodec: Check for bitstream end in read_quant_matrix_ext()

Fixes: out of array read
Fixes: asff-crash-0e53d0dc491dfdd507530b66562812fbd4c36678
Found-by: 's avatarPaul Ch <paulcher@icloud.com>
Signed-off-by: 's avatarMichael Niedermayer <michael@niedermayer.cc>
parent e37741d2
...@@ -2867,11 +2867,13 @@ static int decode_vop_header(Mpeg4DecContext *ctx, GetBitContext *gb) ...@@ -2867,11 +2867,13 @@ static int decode_vop_header(Mpeg4DecContext *ctx, GetBitContext *gb)
return 0; return 0;
} }
static void read_quant_matrix_ext(MpegEncContext *s, GetBitContext *gb) static int read_quant_matrix_ext(MpegEncContext *s, GetBitContext *gb)
{ {
int i, j, v; int i, j, v;
if (get_bits1(gb)) { if (get_bits1(gb)) {
if (get_bits_left(gb) < 64*8)
return AVERROR_INVALIDDATA;
/* intra_quantiser_matrix */ /* intra_quantiser_matrix */
for (i = 0; i < 64; i++) { for (i = 0; i < 64; i++) {
v = get_bits(gb, 8); v = get_bits(gb, 8);
...@@ -2882,6 +2884,8 @@ static void read_quant_matrix_ext(MpegEncContext *s, GetBitContext *gb) ...@@ -2882,6 +2884,8 @@ static void read_quant_matrix_ext(MpegEncContext *s, GetBitContext *gb)
} }
if (get_bits1(gb)) { if (get_bits1(gb)) {
if (get_bits_left(gb) < 64*8)
return AVERROR_INVALIDDATA;
/* non_intra_quantiser_matrix */ /* non_intra_quantiser_matrix */
for (i = 0; i < 64; i++) { for (i = 0; i < 64; i++) {
get_bits(gb, 8); get_bits(gb, 8);
...@@ -2889,6 +2893,8 @@ static void read_quant_matrix_ext(MpegEncContext *s, GetBitContext *gb) ...@@ -2889,6 +2893,8 @@ static void read_quant_matrix_ext(MpegEncContext *s, GetBitContext *gb)
} }
if (get_bits1(gb)) { if (get_bits1(gb)) {
if (get_bits_left(gb) < 64*8)
return AVERROR_INVALIDDATA;
/* chroma_intra_quantiser_matrix */ /* chroma_intra_quantiser_matrix */
for (i = 0; i < 64; i++) { for (i = 0; i < 64; i++) {
v = get_bits(gb, 8); v = get_bits(gb, 8);
...@@ -2898,6 +2904,8 @@ static void read_quant_matrix_ext(MpegEncContext *s, GetBitContext *gb) ...@@ -2898,6 +2904,8 @@ static void read_quant_matrix_ext(MpegEncContext *s, GetBitContext *gb)
} }
if (get_bits1(gb)) { if (get_bits1(gb)) {
if (get_bits_left(gb) < 64*8)
return AVERROR_INVALIDDATA;
/* chroma_non_intra_quantiser_matrix */ /* chroma_non_intra_quantiser_matrix */
for (i = 0; i < 64; i++) { for (i = 0; i < 64; i++) {
get_bits(gb, 8); get_bits(gb, 8);
...@@ -2905,6 +2913,7 @@ static void read_quant_matrix_ext(MpegEncContext *s, GetBitContext *gb) ...@@ -2905,6 +2913,7 @@ static void read_quant_matrix_ext(MpegEncContext *s, GetBitContext *gb)
} }
next_start_code_studio(gb); next_start_code_studio(gb);
return 0;
} }
static void extension_and_user_data(MpegEncContext *s, GetBitContext *gb, int id) static void extension_and_user_data(MpegEncContext *s, GetBitContext *gb, int id)
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment