From patchwork Wed May 11 14:48:16 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Lance Wang X-Patchwork-Id: 35730 Delivered-To: ffmpegpatchwork2@gmail.com Received: by 2002:a05:6a20:a885:b0:7f:4be2:bd17 with SMTP id ca5csp3933898pzb; Wed, 11 May 2022 07:49:24 -0700 (PDT) X-Google-Smtp-Source: ABdhPJyNsj7tCs2NLDoR4xE20acgAA7SzprG1FZuH5Q1Ke4Ash0ol55rjAJIcIvlnOZthQ+rqDse X-Received: by 2002:a17:907:d06:b0:6f4:13cc:80c2 with SMTP id gn6-20020a1709070d0600b006f413cc80c2mr24932580ejc.500.1652280564031; Wed, 11 May 2022 07:49:24 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1652280564; cv=none; d=google.com; s=arc-20160816; b=bh4xWk5NDcD94+DW7vbXH05qgSCIVziRJFjgfql26fH+cSR+NG3cnKo9/DKvpmuwDc zr5MtzA1m/j64b4Md/P8okxUTInlIfD7JUBHptpK9WNtJr10KEWUUkY9/i0KoglLjzS+ mR/r9QYX+58/opja4dvNdAvoptEccnHYGtmFn4bDonvNZ/Q1G2w3Vtif7zEpFwCj/yP+ eDxmiEPalcTpYJfxpeDgEMKCxGz8cDLJp1iifezq2aPOl45iZYfxRysQqEK1I/dJyZwj t7N9dEoK6BPacae7V2pzwZoVzhb4CyzOACTnP8vuq857e0/Sl8v0rjVB9cdWlhYQE54c EdBg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:content-transfer-encoding:mime-version:cc:reply-to :list-subscribe:list-help:list-post:list-archive:list-unsubscribe :list-id:precedence:subject:references:in-reply-to:message-id:date :to:from:dkim-signature:delivered-to; bh=YjovFS5/swJpBImcHXXnYUA2PHFDmvRIhdDDJy/UHcg=; b=Q5Zz1iiiBnrpvVeQGGt6f7JqQamwdVfv46ypu9rZzqpZC/Z1iw3K96Zqj7PuFSAFFQ C5W5zU4BLk4Uh15G4RPth3przfQq4TmKxBll23My1kjo3bWaE0Ndbah3U/OWZYZcIrMg FxelZMA25RdHmY0Esk3TuYBZHuAKrPODTUg7m0UjGuawySFe9aj0Yfr5eCBlJb1RVZbh dsy8uVPqTrjn/EJypnRSMFrYfwezo+VbWqtNTLG5RKHdSytEawNIv0KQCf+JA4V4BQTp uG7c4RgnZS5YFw1ici2/M3Mj1qsYhmxX/L8KxoO9i3qqw1gqto1hE9msRIgGEN5qlE1f L8Xg== ARC-Authentication-Results: i=1; mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20210112 header.b=bYj2vemH; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org. [79.124.17.100]) by mx.google.com with ESMTP id gs12-20020a1709072d0c00b006e8bf488698si2939872ejc.202.2022.05.11.07.49.00; Wed, 11 May 2022 07:49:24 -0700 (PDT) Received-SPF: pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) client-ip=79.124.17.100; Authentication-Results: mx.google.com; dkim=neutral (body hash did not verify) header.i=@gmail.com header.s=20210112 header.b=bYj2vemH; spf=pass (google.com: domain of ffmpeg-devel-bounces@ffmpeg.org designates 79.124.17.100 as permitted sender) smtp.mailfrom=ffmpeg-devel-bounces@ffmpeg.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id 79E6268B410; Wed, 11 May 2022 17:48:33 +0300 (EEST) X-Original-To: ffmpeg-devel@ffmpeg.org Delivered-To: ffmpeg-devel@ffmpeg.org Received: from mail-pl1-f178.google.com (mail-pl1-f178.google.com [209.85.214.178]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id 26CCC68B3EF for ; Wed, 11 May 2022 17:48:27 +0300 (EEST) Received: by mail-pl1-f178.google.com with SMTP id q18so2078365pln.12 for ; Wed, 11 May 2022 07:48:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=NNP0pD+EpFcAgUWgJfYcpv1RRKTidb9y4kLV11fNo8Y=; b=bYj2vemHVygdgypJdYzSx2TcyhNXeoDuac9/X+bJJA+skFUcZ9aSLeXJiK8+6dwktg G4l0ST0dWtJWlgEs6k7yoCRgpKhBKdTx6jqlFBqNkD1Z/utAFgL/EDV06WR1E2Y2Hz/A woLIhodQxadDVGRbmK0ADchFKCftl/9zSAHMDED2dkQ//SKpEmMrVo1gE93UmT7luM3v Ae7GwYZV4EJ2rf9Bg6NCgd+pX/4opi8Tw6hVGGE12Sy8CxjWqoTf3lm00rQ984O5opBd eLfTqqecky1iIdFRGOzKOZoxjiJDJ8Zhe7hV52ZnAurfg/4qOZrOVhNM3zu7FXjrMOBx XiRQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=NNP0pD+EpFcAgUWgJfYcpv1RRKTidb9y4kLV11fNo8Y=; b=qTpUxanr6fYO8/i5CVbxH4GqOivPgzj6AYPe4jPisnnXVk1lWds9fUrEfZHbpKFZNx qVvkRqhW6WuO57wUx9SDKKXGYs7I0qhSt4dbxrDD6IydPYWHOplDjgYAPSW9CbFupq+S VN1eHzWZ0/U9QshUEDJrgRLTLTMKd+VnGuCIIc1VjMIVwJOu66eL/BGiim1UuDweQxLJ ptM/XbRy7rcc87u1FGm/gepItKGa/IR/SZcz1bn45tEOCacPnIwYUs+FJAdcDLKekW3g 2jnIT0qVuNA5vn44AauAUx+VPuSOehzqAywAUyr78l0XVT2MWWRhOfl18XBpjqeI0zUx CNsA== X-Gm-Message-State: AOAM532AMaroZEhlNn5PoPrCF3elekGmCEwfBmRBbSh4iuEUBmkjg6uB CxrsB/0R0RBhLaVrGjMAFJeBKPEUtN8= X-Received: by 2002:a17:902:ab59:b0:15c:f4f3:7e3b with SMTP id ij25-20020a170902ab5900b0015cf4f37e3bmr26365540plb.24.1652280505360; Wed, 11 May 2022 07:48:25 -0700 (PDT) Received: from vpn2.localdomain ([161.117.202.209]) by smtp.gmail.com with ESMTPSA id n17-20020a170903111100b0015e8d4eb2c6sm2059020plh.272.2022.05.11.07.48.24 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 11 May 2022 07:48:25 -0700 (PDT) From: lance.lmwang@gmail.com To: ffmpeg-devel@ffmpeg.org Date: Wed, 11 May 2022 22:48:16 +0800 Message-Id: <1652280498-10408-2-git-send-email-lance.lmwang@gmail.com> X-Mailer: git-send-email 1.8.3.1 In-Reply-To: <1652280498-10408-1-git-send-email-lance.lmwang@gmail.com> References: <1652280498-10408-1-git-send-email-lance.lmwang@gmail.com> Subject: [FFmpeg-devel] [PATCH 2/4] avcodec/ccaption_dec: check the length of packet and return used length X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: FFmpeg development discussions and patches Cc: Limin Wang MIME-Version: 1.0 Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" X-TUID: nTWN04iTgc7m From: Limin Wang Signed-off-by: Limin Wang --- libavcodec/ccaption_dec.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/libavcodec/ccaption_dec.c b/libavcodec/ccaption_dec.c index 34f0513b1a..8f61e8aa03 100644 --- a/libavcodec/ccaption_dec.c +++ b/libavcodec/ccaption_dec.c @@ -852,6 +852,11 @@ static int decode(AVCodecContext *avctx, AVSubtitle *sub, int i; unsigned nb_rect_allocated = 0; + if (len < 3) { + ff_dlog(avctx, "incomplete or broken packet"); + return len; + } + for (i = 0; i < len; i += 3) { uint8_t hi, cc_type = bptr[i] & 1; @@ -922,7 +927,7 @@ static int decode(AVCodecContext *avctx, AVSubtitle *sub, } *got_sub = sub->num_rects > 0; - return ret; + return len; } #define OFFSET(x) offsetof(CCaptionSubContext, x)