Commit f5d03984 authored by Michael Niedermayer's avatar Michael Niedermayer

avformat/swfdec: clear 4 bytes at the end of a packet if they are not initialized

Fixes use of uninitialized memory
Fixes part of msan_uninit-mem_7f055dd0ab1b_9558_videopop_guitar_300k.swf
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: 's avatarMichael Niedermayer <michaelni@gmx.at>
parent e72f5abb
...@@ -455,6 +455,7 @@ bitmap_end_skip: ...@@ -455,6 +455,7 @@ bitmap_end_skip:
/* old SWF files containing SOI/EOI as data start */ /* old SWF files containing SOI/EOI as data start */
/* files created by swink have reversed tag */ /* files created by swink have reversed tag */
pkt->size -= 4; pkt->size -= 4;
memset(pkt->data+pkt->size, 0, 4);
res = avio_read(pb, pkt->data, pkt->size); res = avio_read(pb, pkt->data, pkt->size);
} else { } else {
res = avio_read(pb, pkt->data + 4, pkt->size - 4); res = avio_read(pb, pkt->data + 4, pkt->size - 4);
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment