Message ID | 20240326001151.12083-6-michael@niedermayer.cc |
---|---|
State | Accepted |
Commit | 0bed22d597b78999151e3bde0768b7fe763fc2a6 |
Headers | show |
Series | [FFmpeg-devel,01/10] avformat/concatdec: Check user_duration sum | expand |
Context | Check | Description |
---|---|---|
andriy/configure_x86 | warning | Failed to apply patch |
yinshiyou/configure_loongarch64 | warning | Failed to apply patch |
diff --git a/libavformat/sbgdec.c b/libavformat/sbgdec.c index bc2469afd17..e60eb1481ea 100644 --- a/libavformat/sbgdec.c +++ b/libavformat/sbgdec.c @@ -387,7 +387,7 @@ static int parse_options(struct sbg_parser *p) case 'L': FORWARD_ERROR(parse_optarg(p, opt, &oarg)); r = str_to_time(oarg.s, &p->scs.opt_duration); - if (oarg.e != oarg.s + r) { + if (oarg.e != oarg.s + r || p->scs.opt_duration < 0) { snprintf(p->err_msg, sizeof(p->err_msg), "syntax error for option -L"); return AVERROR_INVALIDDATA;
Fixes: signed integer overflow: 9223372036854775807 - -8000000 cannot be represented in type 'long' Fixes: 62276/clusterfuzz-testcase-minimized-ffmpeg_dem_SBG_fuzzer-5133181743136768 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> --- libavformat/sbgdec.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)