Commit a2b8dde6 authored by Michael Niedermayer's avatar Michael Niedermayer

avcodec/idcinvideo: Check side data size before use

Fixes out of array read
Signed-off-by: 's avatarMichael Niedermayer <michael@niedermayer.cc>
parent e8634fb9
...@@ -214,7 +214,8 @@ static int idcin_decode_frame(AVCodecContext *avctx, ...@@ -214,7 +214,8 @@ static int idcin_decode_frame(AVCodecContext *avctx,
const uint8_t *buf = avpkt->data; const uint8_t *buf = avpkt->data;
int buf_size = avpkt->size; int buf_size = avpkt->size;
IdcinContext *s = avctx->priv_data; IdcinContext *s = avctx->priv_data;
const uint8_t *pal = av_packet_get_side_data(avpkt, AV_PKT_DATA_PALETTE, NULL); int pal_size;
const uint8_t *pal = av_packet_get_side_data(avpkt, AV_PKT_DATA_PALETTE, &pal_size);
AVFrame *frame = data; AVFrame *frame = data;
int ret; int ret;
...@@ -227,9 +228,11 @@ static int idcin_decode_frame(AVCodecContext *avctx, ...@@ -227,9 +228,11 @@ static int idcin_decode_frame(AVCodecContext *avctx,
if (idcin_decode_vlcs(s, frame)) if (idcin_decode_vlcs(s, frame))
return AVERROR_INVALIDDATA; return AVERROR_INVALIDDATA;
if (pal) { if (pal && pal_size == AVPALETTE_SIZE) {
frame->palette_has_changed = 1; frame->palette_has_changed = 1;
memcpy(s->pal, pal, AVPALETTE_SIZE); memcpy(s->pal, pal, AVPALETTE_SIZE);
} else if (pal) {
av_log(avctx, AV_LOG_ERROR, "Palette size %d is wrong\n", pal_size);
} }
/* make the palette available on the way out */ /* make the palette available on the way out */
memcpy(frame->data[1], s->pal, AVPALETTE_SIZE); memcpy(frame->data[1], s->pal, AVPALETTE_SIZE);
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment