[FFmpeg-cvslog] tools/target_dec_fuzzer: Fuzz video decoder related fields in context.

Michael Niedermayer git at videolan.org
Thu Apr 20 00:54:22 EEST 2017


ffmpeg | branch: master | Michael Niedermayer <michael at niedermayer.cc> | Wed Apr 19 22:58:27 2017 +0200| [164758a831b13c8a0fa1ba7d84e53dffcea2904a] | committer: Michael Niedermayer

tools/target_dec_fuzzer: Fuzz video decoder related fields in context.

Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=164758a831b13c8a0fa1ba7d84e53dffcea2904a
---

 tools/target_dec_fuzzer.c | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/tools/target_dec_fuzzer.c b/tools/target_dec_fuzzer.c
index cb3bc50919..43442a3616 100644
--- a/tools/target_dec_fuzzer.c
+++ b/tools/target_dec_fuzzer.c
@@ -49,6 +49,7 @@
 #include "libavutil/intreadwrite.h"
 
 #include "libavcodec/avcodec.h"
+#include "libavcodec/bytestream.h"
 #include "libavformat/avformat.h"
 
 static void error(const char *err)
@@ -151,6 +152,18 @@ int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
 
     ctx->max_pixels = 4096 * 4096; //To reduce false positive OOM and hangs
 
+    if (size > 1024) {
+        GetByteContext gbc;
+        bytestream2_init(&gbc, data + size - 1024, 1024);
+        ctx->width                              = bytestream2_get_le32(&gbc);
+        ctx->height                             = bytestream2_get_le32(&gbc);
+        ctx->bit_rate                           = bytestream2_get_le64(&gbc);
+        ctx->bits_per_coded_sample              = bytestream2_get_le32(&gbc);
+        if (av_image_check_size(ctx->width, ctx->height, 0, ctx))
+            ctx->width = ctx->height = 0;
+        size -= 1024;
+    }
+
     int res = avcodec_open2(ctx, c, NULL);
     if (res < 0)
         return res;



More information about the ffmpeg-cvslog mailing list