diff options
author | Michael Niedermayer <michaelni@gmx.at> | 2013-11-22 16:51:07 +0100 |
---|---|---|
committer | Michael Niedermayer <michaelni@gmx.at> | 2014-01-08 00:25:07 +0100 |
commit | d1a91958631754359566c73aaf9a296a0710796a (patch) | |
tree | ec247cb068c7831c06906e54f3a69271654ab9ce /libavcodec/mjpegdec.c | |
parent | 898ab02557b0f9a3d6245b72c3d454f1417f7e3f (diff) | |
download | android_external_ffmpeg-d1a91958631754359566c73aaf9a296a0710796a.tar.gz android_external_ffmpeg-d1a91958631754359566c73aaf9a296a0710796a.tar.bz2 android_external_ffmpeg-d1a91958631754359566c73aaf9a296a0710796a.zip |
avcodec/mjpegdec: check len in mjpeg_decode_app() more completely
Avoids len from becoming negative and causing assertion failure
Fixes: signal_sigabrt_7ffff7126425_5140_fd44dc63fa7bdd12ee34fc602231ef02.jpg
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
(cherry picked from commit 6060234d43dcf0b5200cdd7dbd2f1542146827eb)
Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
Diffstat (limited to 'libavcodec/mjpegdec.c')
-rw-r--r-- | libavcodec/mjpegdec.c | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/libavcodec/mjpegdec.c b/libavcodec/mjpegdec.c index f4e082f05b..398d758a8c 100644 --- a/libavcodec/mjpegdec.c +++ b/libavcodec/mjpegdec.c @@ -1444,7 +1444,7 @@ static int mjpeg_decode_app(MJpegDecodeContext *s) int len, id, i; len = get_bits(&s->gb, 16); - if (len < 5) + if (len < 6) return AVERROR_INVALIDDATA; if (8 * len > get_bits_left(&s->gb)) return AVERROR_INVALIDDATA; @@ -1558,7 +1558,7 @@ static int mjpeg_decode_app(MJpegDecodeContext *s) } /* EXIF metadata */ - if (s->start_code == APP1 && id == AV_RB32("Exif")) { + if (s->start_code == APP1 && id == AV_RB32("Exif") && len >= 2) { GetByteContext gbytes; int ret, le, ifd_offset, bytes_read; const uint8_t *aligned; |