Commit d0dafebb authored by Michael Niedermayer's avatar Michael Niedermayer

tm2: Fix overread of token array.

Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: 's avatarMichael Niedermayer <michaelni@gmx.at>
parent 11cc2092
......@@ -339,8 +339,13 @@ static inline int GET_TOK(TM2Context *ctx,int type) {
av_log(ctx->avctx, AV_LOG_ERROR, "Read token from stream %i out of bounds (%i>=%i)\n", type, ctx->tok_ptrs[type], ctx->tok_lens[type]);
return 0;
}
if(type <= TM2_MOT)
if(type <= TM2_MOT) {
if (ctx->tokens[type][ctx->tok_ptrs[type]] >= TM2_DELTAS) {
av_log(ctx->avctx, AV_LOG_ERROR, "token %d is too large\n", ctx->tokens[type][ctx->tok_ptrs[type]]);
return 0;
}
return ctx->deltas[type][ctx->tokens[type][ctx->tok_ptrs[type]++]];
}
return ctx->tokens[type][ctx->tok_ptrs[type]++];
}
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment