]> git.sesse.net Git - ffmpeg/commitdiff
avcodec/diracdec: Check slice numbers for overflows in relation to picture dimensions
authorMichael Niedermayer <michael@niedermayer.cc>
Sun, 22 Jul 2018 19:26:24 +0000 (21:26 +0200)
committerMichael Niedermayer <michael@niedermayer.cc>
Sat, 28 Jul 2018 12:35:50 +0000 (14:35 +0200)
Fixes: signed integer overflow: 88 * 33685506 cannot be represented in type 'int'
Fixes: 9433/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_DIRAC_fuzzer-5725943535501312
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
libavcodec/diracdec.c

index 4ef1b3ea9b2da24521eef9cf2955638b3faa838c..b27c743c583dc388e581a486d995737c62beaec0 100644 (file)
@@ -1243,7 +1243,10 @@ static int dirac_unpack_idwt_params(DiracContext *s)
     else {
         s->num_x        = get_interleaved_ue_golomb(gb);
         s->num_y        = get_interleaved_ue_golomb(gb);
-        if (s->num_x * s->num_y == 0 || s->num_x * (uint64_t)s->num_y > INT_MAX) {
+        if (s->num_x * s->num_y == 0 || s->num_x * (uint64_t)s->num_y > INT_MAX ||
+            s->num_x * (uint64_t)s->avctx->width  > INT_MAX ||
+            s->num_y * (uint64_t)s->avctx->height > INT_MAX
+        ) {
             av_log(s->avctx,AV_LOG_ERROR,"Invalid numx/y\n");
             s->num_x = s->num_y = 0;
             return AVERROR_INVALIDDATA;