[FFmpeg-cvslog] avcodec/hevc: Check num_entry_point_offsets
Michael Niedermayer
git at videolan.org
Sat May 16 00:16:19 CEST 2015
ffmpeg | branch: release/2.6 | Michael Niedermayer <michaelni at gmx.at> | Wed May 13 13:21:52 2015 +0200| [bced2ad1bd53bde54139161cc35b97b57a787732] | committer: Michael Niedermayer
avcodec/hevc: Check num_entry_point_offsets
Fixes CID1239099 part 2
Signed-off-by: Michael Niedermayer <michaelni at gmx.at>
(cherry picked from commit 1c6ae98d4a9ff9ea607df87908393eda4ebdf4e8)
Signed-off-by: Michael Niedermayer <michaelni at gmx.at>
> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=bced2ad1bd53bde54139161cc35b97b57a787732
---
libavcodec/hevc.c | 9 ++++++++-
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/libavcodec/hevc.c b/libavcodec/hevc.c
index dfc5616..63c5688 100644
--- a/libavcodec/hevc.c
+++ b/libavcodec/hevc.c
@@ -694,7 +694,14 @@ static int hls_slice_header(HEVCContext *s)
sh->num_entry_point_offsets = 0;
if (s->pps->tiles_enabled_flag || s->pps->entropy_coding_sync_enabled_flag) {
- sh->num_entry_point_offsets = get_ue_golomb_long(gb);
+ unsigned num_entry_point_offsets = get_ue_golomb_long(gb);
+ // It would be possible to bound this tighter but this here is simpler
+ if (sh->num_entry_point_offsets > get_bits_left(gb)) {
+ av_log(s->avctx, AV_LOG_ERROR, "num_entry_point_offsets %d is invalid\n", num_entry_point_offsets);
+ return AVERROR_INVALIDDATA;
+ }
+
+ sh->num_entry_point_offsets = num_entry_point_offsets;
if (sh->num_entry_point_offsets > 0) {
int offset_len = get_ue_golomb_long(gb) + 1;
int segments = offset_len >> 4;
More information about the ffmpeg-cvslog
mailing list