error_concealment: avoid using the picture if not fully setup
authorMichael Niedermayer <michaelni@gmx.at>
Wed, 6 Aug 2014 17:19:57 +0000 (18:19 +0100)
committerAnton Khirnov <anton@khirnov.net>
Wed, 6 Aug 2014 19:25:56 +0000 (19:25 +0000)
Fixes state becoming inconsistent and a null pointer dereference.

CC: libav-stable@libav.org
Bug-Id: CVE-2013-0860
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: Vittorio Giovara <vittorio.giovara@gmail.com>
Signed-off-by: Anton Khirnov <anton@khirnov.net>
libavcodec/error_resilience.c

index ae9ef68..73b69af 100644 (file)
@@ -896,6 +896,12 @@ void ff_er_frame_end(MpegEncContext *s)
         return;
     };
 
         return;
     };
 
+    if (s->picture_structure == PICT_FRAME &&
+        s->current_picture.f.linesize[0] != s->current_picture_ptr->f.linesize[0]) {
+        av_log(s->avctx, AV_LOG_ERROR, "Error concealment not possible, frame not fully initialized\n");
+        return;
+    }
+
     if (s->current_picture.f.motion_val[0] == NULL) {
         av_log(s->avctx, AV_LOG_ERROR, "Warning MVs not available\n");
 
     if (s->current_picture.f.motion_val[0] == NULL) {
         av_log(s->avctx, AV_LOG_ERROR, "Warning MVs not available\n");