Message ID | 20181020223512.17335-2-michael@niedermayer.cc |
---|---|
State | Accepted |
Commit | e90f0ac334f2bec0961955dceb824148594a4016 |
Headers | show |
On 10/21/18, Michael Niedermayer <michael@niedermayer.cc> wrote: > Fixes: Out of array read > Fixes: > 10789/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_ILBC_fuzzer-5153255445757952 > > Found-by: continuous fuzzing process > https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg > Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> > --- > libavcodec/ilbcdec.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > LGTM
On Sun, Oct 21, 2018 at 06:21:32PM +0200, Paul B Mahol wrote: > On 10/21/18, Michael Niedermayer <michael@niedermayer.cc> wrote: > > Fixes: Out of array read > > Fixes: > > 10789/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_ILBC_fuzzer-5153255445757952 > > > > Found-by: continuous fuzzing process > > https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg > > Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> > > --- > > libavcodec/ilbcdec.c | 2 +- > > 1 file changed, 1 insertion(+), 1 deletion(-) > > > > LGTM will apply thx [...]
diff --git a/libavcodec/ilbcdec.c b/libavcodec/ilbcdec.c index 8f234b98e1..8a6dbe0b75 100644 --- a/libavcodec/ilbcdec.c +++ b/libavcodec/ilbcdec.c @@ -1372,7 +1372,7 @@ static int ilbc_decode_frame(AVCodecContext *avctx, void *data, if (unpack_frame(s)) mode = 0; - if (s->frame.start < 1) + if (s->frame.start < 1 || s->frame.start > 5) mode = 0; if (mode) {
Fixes: Out of array read Fixes: 10789/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_ILBC_fuzzer-5153255445757952 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> --- libavcodec/ilbcdec.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)