[FFmpeg-cvslog] lavc/jpeg2000dec: Fix jp2 inner atom size used for overread checks.

Carl Eugen Hoyos git at videolan.org
Wed May 3 04:46:11 EEST 2017


ffmpeg | branch: master | Carl Eugen Hoyos <cehoyos at ag.or.at> | Tue May  2 16:09:11 2017 +0200| [a75ef1506a62ff21f3e282d76978b28ffc305c64] | committer: Carl Eugen Hoyos

lavc/jpeg2000dec: Fix jp2 inner atom size used for overread checks.

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=a75ef1506a62ff21f3e282d76978b28ffc305c64
---

 libavcodec/jpeg2000dec.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/libavcodec/jpeg2000dec.c b/libavcodec/jpeg2000dec.c
index e9f5f51af3..ab814cabe5 100644
--- a/libavcodec/jpeg2000dec.c
+++ b/libavcodec/jpeg2000dec.c
@@ -1982,6 +1982,7 @@ static int jp2_find_codestream(Jpeg2000DecoderContext *s)
                 atom2_end  = bytestream2_tell(&s->g) + atom2_size - 8;
                 if (atom2_size < 8 || atom2_end > atom_end || atom2_end < atom2_size)
                     break;
+                atom2_size -= 8;
                 if (atom2 == JP2_CODESTREAM) {
                     return 1;
                 } else if (atom2 == MKBETAG('c','o','l','r') && atom2_size >= 7) {



More information about the ffmpeg-cvslog mailing list