[FFmpeg-cvslog] mpc7: check subband index

Michael Niedermayer git at videolan.org
Sat Mar 10 23:16:16 CET 2012


ffmpeg | branch: master | Michael Niedermayer <michaelni at gmx.at> | Sat Mar 10 22:36:15 2012 +0100| [8e9a0a3568d915387c35645ea7d85945b98d2197] | committer: Michael Niedermayer

mpc7: check subband index

This fixes a overread

Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: Michael Niedermayer <michaelni at gmx.at>

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=8e9a0a3568d915387c35645ea7d85945b98d2197
---

 libavcodec/mpc7.c |    4 ++++
 1 files changed, 4 insertions(+), 0 deletions(-)

diff --git a/libavcodec/mpc7.c b/libavcodec/mpc7.c
index 6e4b850..711f0da 100644
--- a/libavcodec/mpc7.c
+++ b/libavcodec/mpc7.c
@@ -248,6 +248,10 @@ static int mpc7_decode_frame(AVCodecContext * avctx, void *data,
             if(i) t = get_vlc2(&gb, hdr_vlc.table, MPC7_HDR_BITS, 1) - 5;
             if(t == 4) bands[i].res[ch] = get_bits(&gb, 4);
             else bands[i].res[ch] = bands[i-1].res[ch] + t;
+            if (bands[i].res[ch] < -1 || bands[i].res[ch] > 17) {
+                av_log(avctx, AV_LOG_ERROR, "subband index invalid\n");
+                return AVERROR_INVALIDDATA;
+            }
         }
 
         if(bands[i].res[0] || bands[i].res[1]){



More information about the ffmpeg-cvslog mailing list