Commit 6138ed77 authored by Michael Niedermayer's avatar Michael Niedermayer

Arrays where one element too small, fixes CID114.

this was possibly exploitable

Originally committed as revision 13475 to svn://svn.ffmpeg.org/ffmpeg/trunk
parent 5e5c9086
......@@ -116,8 +116,8 @@ static int decode_residual_block(AVSContext *h, GetBitContext *gb,
const dec_2dvlc_t *r, int esc_golomb_order,
int qp, uint8_t *dst, int stride) {
int i, level_code, esc_code, level, run, mask;
DCTELEM level_buf[64];
uint8_t run_buf[64];
DCTELEM level_buf[65];
uint8_t run_buf[65];
DCTELEM *block = h->block;
for(i=0;i<65;i++) {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment