mirror of
https://github.com/FFmpeg/FFmpeg.git
synced 2026-08-09 01:21:06 +00:00
avcodec/screenpresso: reject deflate output shorter than the frame
Fixes: use of uninitialized memory Fixes: screenpresso_short_zlib_heap_disclosure.avi Fixes: ksUBwBOjJodq Found-by: Adrian Junge (vurlo)
This commit is contained in:
committed by
michaelni
parent
7002e01c19
commit
7058900614
@@ -137,6 +137,9 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, AVFrame *frame,
|
||||
return AVERROR_INVALIDDATA;
|
||||
}
|
||||
|
||||
/* Codec has aligned strides */
|
||||
src_linesize = FFALIGN(avctx->width * component_size, 4);
|
||||
|
||||
/* Inflate the frame after the 2 byte header */
|
||||
ret = uncompress(ctx->inflated_buf, &length,
|
||||
avpkt->data + 2, avpkt->size - 2);
|
||||
@@ -144,14 +147,16 @@ static int screenpresso_decode_frame(AVCodecContext *avctx, AVFrame *frame,
|
||||
av_log(avctx, AV_LOG_ERROR, "Deflate error %d.\n", ret);
|
||||
return AVERROR_UNKNOWN;
|
||||
}
|
||||
if (length < src_linesize * avctx->height) {
|
||||
av_log(avctx, AV_LOG_ERROR, "Deflated %lu bytes, but %d are needed\n",
|
||||
length, src_linesize * avctx->height);
|
||||
return AVERROR_INVALIDDATA;
|
||||
}
|
||||
|
||||
ret = ff_reget_buffer(avctx, ctx->current, 0);
|
||||
if (ret < 0)
|
||||
return ret;
|
||||
|
||||
/* Codec has aligned strides */
|
||||
src_linesize = FFALIGN(avctx->width * component_size, 4);
|
||||
|
||||
/* When a keyframe is found, copy it (flipped) */
|
||||
if (keyframe)
|
||||
av_image_copy_plane(ctx->current->data[0] +
|
||||
|
||||
Reference in New Issue
Block a user