Message ID | 20240326001151.12083-9-michael@niedermayer.cc |
---|---|
State | Accepted |
Commit | e849eb23432e45d0a1fda3901bb84eff0ce91282 |
Headers | show |
Series | [FFmpeg-devel,01/10] avformat/concatdec: Check user_duration sum | expand |
Context | Check | Description |
---|---|---|
andriy/configure_x86 | warning | Failed to apply patch |
yinshiyou/configure_loongarch64 | warning | Failed to apply patch |
diff --git a/libavformat/matroskadec.c b/libavformat/matroskadec.c index 8897fd622c6..8e031c618ba 100644 --- a/libavformat/matroskadec.c +++ b/libavformat/matroskadec.c @@ -3195,6 +3195,10 @@ static int matroska_parse_tracks(AVFormatContext *s) track->time_scale); track->time_scale = 1.0; } + + if (matroska->time_scale * track->time_scale > UINT_MAX) + return AVERROR_INVALIDDATA; + avpriv_set_pts_info(st, 64, matroska->time_scale * track->time_scale, 1000 * 1000 * 1000); /* 64 bit pts in ns */
Fixes: 3.82046e+18 is outside the range of representable values of type 'unsigned int' Fixes: 62276/clusterfuzz-testcase-minimized-ffmpeg_dem_WEBM_DASH_MANIFEST_fuzzer-6381436594421760 Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> --- libavformat/matroskadec.c | 4 ++++ 1 file changed, 4 insertions(+)