]> git.sesse.net Git - ffmpeg/commitdiff
avcodec/qpeg: Limit copy in qpeg_decode_intra() to the available bytes
authorMichael Niedermayer <michael@niedermayer.cc>
Sat, 23 Feb 2019 23:44:40 +0000 (00:44 +0100)
committerMichael Niedermayer <michael@niedermayer.cc>
Sun, 3 Mar 2019 12:17:02 +0000 (13:17 +0100)
Fixes: Timeout (27 sec -> 39 milli sec)
Fixes: 13151/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_QPEG_fuzzer-5717536023248896
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
libavcodec/qpeg.c

index 654fd998d6abb11efaa7546ca3f7518dfe6b5dd0..d4195c5f0b7f145e7bbbf28dc894c8e0bed4b9ab 100644 (file)
@@ -99,6 +99,8 @@ static void qpeg_decode_intra(QpegContext *qctx, uint8_t *dst,
                 }
             }
         } else {
+            if (bytestream2_get_bytes_left(&qctx->buffer) < copy)
+                copy = bytestream2_get_bytes_left(&qctx->buffer);
             for(i = 0; i < copy; i++) {
                 dst[filled++] = bytestream2_get_byte(&qctx->buffer);
                 if (filled >= width) {