[FFmpeg-devel] [PATCH 1/3] tools/target_dec_fuzzer: Init parsepkt

James Almer jamrial at gmail.com
Sat Aug 31 02:51:53 EEST 2019


On 8/30/2019 8:25 PM, Michael Niedermayer wrote:
> Fixes: memory corruption
> Fixes: 16702/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_PNG_fuzzer-5768418552184832
> 
> Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
> Signed-off-by: Michael Niedermayer <michael at niedermayer.cc>
> ---
>  tools/target_dec_fuzzer.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/tools/target_dec_fuzzer.c b/tools/target_dec_fuzzer.c
> index e22a0c5c34..901dbca385 100644
> --- a/tools/target_dec_fuzzer.c
> +++ b/tools/target_dec_fuzzer.c
> @@ -194,6 +194,7 @@ int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) {
>      // Read very simple container
>      AVPacket avpkt, parsepkt;
>      av_init_packet(&avpkt);
> +    av_init_packet(&parsepkt);
>      while (data < end && it < maxiteration) {
>          // Search for the TAG
>          while (data + sizeof(fuzz_tag) < end) {
> 

LGTM.


More information about the ffmpeg-devel mailing list