[FFmpeg-cvslog] exr: check size of uncompressed buffer returned by uncompress()

Paul B Mahol git at videolan.org
Mon Jul 16 03:04:19 CEST 2012


ffmpeg | branch: master | Paul B Mahol <onemda at gmail.com> | Fri Jul 13 02:02:10 2012 +0000| [7543fd80e5c24aa835e4bcf5d8ef02b18f242018] | committer: Paul B Mahol

exr: check size of uncompressed buffer returned by uncompress()

The actual size of uncompressed buffer returned by uncompress() may be
smaller than expected, so abort decoding in such cases.

Signed-off-by: Paul B Mahol <onemda at gmail.com>

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=7543fd80e5c24aa835e4bcf5d8ef02b18f242018
---

 libavcodec/exr.c |    5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/libavcodec/exr.c b/libavcodec/exr.c
index 52e8916..f175706 100644
--- a/libavcodec/exr.c
+++ b/libavcodec/exr.c
@@ -545,7 +545,10 @@ static int decode_frame(AVCodecContext *avctx,
                 const uint8_t *red_channel_buffer, *green_channel_buffer, *blue_channel_buffer, *alpha_channel_buffer = 0;
 
                 if ((s->compr == EXR_ZIP1 || s->compr == EXR_ZIP16) && data_size < uncompressed_size) {
-                    if (uncompress(s->tmp, &uncompressed_size, avpkt->data + line_offset, data_size) != Z_OK) {
+                    unsigned long dest_len = uncompressed_size;
+
+                    if (uncompress(s->tmp, &dest_len, avpkt->data + line_offset, data_size) != Z_OK ||
+                        dest_len != uncompressed_size) {
                         av_log(avctx, AV_LOG_ERROR, "error during zlib decompression\n");
                         return AVERROR(EINVAL);
                     }



More information about the ffmpeg-cvslog mailing list