jvdec: Do not feed the decoder with known wrong data
authorLuca Barbato <lu_zero@gentoo.org>
Fri, 13 Dec 2013 02:07:57 +0000 (03:07 +0100)
committerLuca Barbato <lu_zero@gentoo.org>
Fri, 20 Dec 2013 16:44:20 +0000 (17:44 +0100)
Still assume the size value is right in non-explode mode.

libavformat/jvdec.c

index 6bf220f..17ce326 100644 (file)
@@ -128,10 +128,23 @@ static int read_header(AVFormatContext *s)
         jvf->audio_size = avio_rl32(pb);
         jvf->video_size = avio_rl32(pb);
         jvf->palette_size = avio_r8(pb) ? 768 : 0;
-        jvf->video_size = FFMIN(FFMAX(jvf->video_size, 0),
-                                INT_MAX - JV_PREAMBLE_SIZE - jvf->palette_size);
+
+        if ((jvf->video_size | jvf->audio_size) & ~0xFFFFFF ||
+            e->size - jvf->audio_size
+                    - jvf->video_size
+                    - jvf->palette_size < 0) {
+            if (s->error_recognition & AV_EF_EXPLODE) {
+                read_close(s);
+                return AVERROR_INVALIDDATA;
+            }
+            jvf->audio_size =
+            jvf->video_size =
+            jvf->palette_size = 0;
+        }
+
         if (avio_r8(pb))
              av_log(s, AV_LOG_WARNING, "unsupported audio codec\n");
+
         jvf->video_type = avio_r8(pb);
         avio_skip(pb, 1);