From: Anton Khirnov Date: Fri, 15 Nov 2013 18:06:23 +0000 (+0100) Subject: pcx: round up in bits->bytes conversion in a buffer size check X-Git-Tag: n2.2-rc2~55^2~538 X-Git-Url: http://git.ffmpeg.org/gitweb/ffmpeg.git/commitdiff_plain/430d12196432ded13f011a3bf7690f03c9b2e5d6 pcx: round up in bits->bytes conversion in a buffer size check Fixes invalid reads. Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind CC:libav-stable@libav.org --- diff --git a/libavcodec/pcx.c b/libavcodec/pcx.c index 1a5357b..61c971e 100644 --- a/libavcodec/pcx.c +++ b/libavcodec/pcx.c @@ -109,7 +109,7 @@ static int pcx_decode_frame(AVCodecContext *avctx, void *data, int *got_frame, nplanes = buf[65]; bytes_per_scanline = nplanes * bytes_per_line; - if (bytes_per_scanline < w * bits_per_pixel * nplanes / 8 || + if (bytes_per_scanline < (w * bits_per_pixel * nplanes + 7) / 8 || (!compressed && bytes_per_scanline > buf_size / h)) { av_log(avctx, AV_LOG_ERROR, "PCX data is corrupted\n"); return AVERROR_INVALIDDATA;