avcodec/jpeg2000: Change coord to 32bit to support larger than 32k width or height
Fixes: 03e0abe721b1174856d41a1eb5d6a896/signal_sigabrt_7ffff6ae7cc9_3813_e71bf3541abed3ccba031cd5ba0269a4.avi Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind Signed-off-by: Michael Niedermayer <michael@niedermayer.cc> (cherry picked from commit 0eb7de19736891a9386ab66549f780e904a3b6a7) Signed-off-by: Andreas Cadhalpun <Andreas.Cadhalpun@googlemail.com>
This commit is contained in:
parent
c3a44a2a55
commit
bdbfc12e7f
@ -213,8 +213,8 @@ int ff_jpeg2000_init_component(Jpeg2000Component *comp,
|
||||
// component size comp->coord is uint16_t so ir cannot overflow
|
||||
csize = (comp->coord[0][1] - comp->coord[0][0]) *
|
||||
(comp->coord[1][1] - comp->coord[1][0]);
|
||||
if (comp->coord[0][1] > 32768 ||
|
||||
comp->coord[1][1] > 32768) {
|
||||
if (comp->coord[0][1] - comp->coord[0][0] > 32768 ||
|
||||
comp->coord[1][1] - comp->coord[1][0] > 32768) {
|
||||
av_log(avctx, AV_LOG_ERROR, "component size too large\n");
|
||||
return AVERROR_PATCHWELCOME;
|
||||
}
|
||||
@ -455,7 +455,7 @@ int ff_jpeg2000_init_component(Jpeg2000Component *comp,
|
||||
return AVERROR(ENOMEM);
|
||||
for (cblkno = 0; cblkno < nb_codeblocks; cblkno++) {
|
||||
Jpeg2000Cblk *cblk = prec->cblk + cblkno;
|
||||
uint16_t Cx0, Cy0;
|
||||
int Cx0, Cy0;
|
||||
|
||||
/* Compute coordinates of codeblocks */
|
||||
/* Compute Cx0*/
|
||||
|
@ -174,21 +174,21 @@ typedef struct Jpeg2000Cblk {
|
||||
int nb_terminationsinc;
|
||||
int data_start[JPEG2000_MAX_PASSES];
|
||||
Jpeg2000Pass passes[JPEG2000_MAX_PASSES];
|
||||
uint16_t coord[2][2]; // border coordinates {{x0, x1}, {y0, y1}}
|
||||
int coord[2][2]; // border coordinates {{x0, x1}, {y0, y1}}
|
||||
} Jpeg2000Cblk; // code block
|
||||
|
||||
typedef struct Jpeg2000Prec {
|
||||
uint16_t nb_codeblocks_width;
|
||||
uint16_t nb_codeblocks_height;
|
||||
int nb_codeblocks_width;
|
||||
int nb_codeblocks_height;
|
||||
Jpeg2000TgtNode *zerobits;
|
||||
Jpeg2000TgtNode *cblkincl;
|
||||
Jpeg2000Cblk *cblk;
|
||||
int decoded_layers;
|
||||
uint16_t coord[2][2]; // border coordinates {{x0, x1}, {y0, y1}}
|
||||
int coord[2][2]; // border coordinates {{x0, x1}, {y0, y1}}
|
||||
} Jpeg2000Prec; // precinct
|
||||
|
||||
typedef struct Jpeg2000Band {
|
||||
uint16_t coord[2][2]; // border coordinates {{x0, x1}, {y0, y1}}
|
||||
int coord[2][2]; // border coordinates {{x0, x1}, {y0, y1}}
|
||||
uint16_t log2_cblk_width, log2_cblk_height;
|
||||
int i_stepsize; // quantization stepsize
|
||||
float f_stepsize; // quantization stepsize
|
||||
@ -197,8 +197,8 @@ typedef struct Jpeg2000Band {
|
||||
|
||||
typedef struct Jpeg2000ResLevel {
|
||||
uint8_t nbands;
|
||||
uint16_t coord[2][2]; // border coordinates {{x0, x1}, {y0, y1}}
|
||||
uint16_t num_precincts_x, num_precincts_y; // number of precincts in x/y direction
|
||||
int coord[2][2]; // border coordinates {{x0, x1}, {y0, y1}}
|
||||
int num_precincts_x, num_precincts_y; // number of precincts in x/y direction
|
||||
uint8_t log2_prec_width, log2_prec_height; // exponent of precinct size
|
||||
Jpeg2000Band *band;
|
||||
} Jpeg2000ResLevel; // resolution level
|
||||
@ -208,8 +208,8 @@ typedef struct Jpeg2000Component {
|
||||
DWTContext dwt;
|
||||
float *f_data;
|
||||
int *i_data;
|
||||
uint16_t coord[2][2]; // border coordinates {{x0, x1}, {y0, y1}} -- can be reduced with lowres option
|
||||
uint16_t coord_o[2][2]; // border coordinates {{x0, x1}, {y0, y1}} -- original values from jpeg2000 headers
|
||||
int coord[2][2]; // border coordinates {{x0, x1}, {y0, y1}} -- can be reduced with lowres option
|
||||
int coord_o[2][2]; // border coordinates {{x0, x1}, {y0, y1}} -- original values from jpeg2000 headers
|
||||
} Jpeg2000Component;
|
||||
|
||||
/* misc tools */
|
||||
|
@ -30,6 +30,7 @@
|
||||
#include "libavutil/attributes.h"
|
||||
#include "libavutil/avassert.h"
|
||||
#include "libavutil/common.h"
|
||||
#include "libavutil/imgutils.h"
|
||||
#include "libavutil/opt.h"
|
||||
#include "libavutil/pixdesc.h"
|
||||
#include "avcodec.h"
|
||||
@ -279,7 +280,7 @@ static int get_siz(Jpeg2000DecoderContext *s)
|
||||
avpriv_request_sample(s->avctx, "Support for image offsets");
|
||||
return AVERROR_PATCHWELCOME;
|
||||
}
|
||||
if (s->width > 32768U || s->height > 32768U) {
|
||||
if (av_image_check_size(s->width, s->height, 0, s->avctx)) {
|
||||
avpriv_request_sample(s->avctx, "Large Dimensions");
|
||||
return AVERROR_PATCHWELCOME;
|
||||
}
|
||||
|
@ -534,7 +534,7 @@ static void dwt_decode97_int(DWTContext *s, int32_t *t)
|
||||
data[i] = (data[i] + ((1<<I_PRESHIFT)>>1)) >> I_PRESHIFT;
|
||||
}
|
||||
|
||||
int ff_jpeg2000_dwt_init(DWTContext *s, uint16_t border[2][2],
|
||||
int ff_jpeg2000_dwt_init(DWTContext *s, int border[2][2],
|
||||
int decomp_levels, int type)
|
||||
{
|
||||
int i, j, lev = decomp_levels, maxlen,
|
||||
@ -623,7 +623,7 @@ void ff_dwt_destroy(DWTContext *s)
|
||||
|
||||
#define MAX_W 256
|
||||
|
||||
static int test_dwt(int *array, int *ref, uint16_t border[2][2], int decomp_levels, int type, int max_diff) {
|
||||
static int test_dwt(int *array, int *ref, int border[2][2], int decomp_levels, int type, int max_diff) {
|
||||
int ret, j;
|
||||
DWTContext s1={{{0}}}, *s= &s1;
|
||||
int64_t err2 = 0;
|
||||
@ -662,7 +662,7 @@ static int test_dwt(int *array, int *ref, uint16_t border[2][2], int decomp_leve
|
||||
return 0;
|
||||
}
|
||||
|
||||
static int test_dwtf(float *array, float *ref, uint16_t border[2][2], int decomp_levels, float max_diff) {
|
||||
static int test_dwtf(float *array, float *ref, int border[2][2], int decomp_levels, float max_diff) {
|
||||
int ret, j;
|
||||
DWTContext s1={{{0}}}, *s= &s1;
|
||||
double err2 = 0;
|
||||
@ -708,7 +708,7 @@ static float reff [MAX_W * MAX_W];
|
||||
int main(void) {
|
||||
AVLFG prng;
|
||||
int i,j;
|
||||
uint16_t border[2][2];
|
||||
int border[2][2];
|
||||
int ret, decomp_levels;
|
||||
|
||||
av_lfg_init(&prng, 1);
|
||||
|
@ -42,7 +42,7 @@ enum DWTType {
|
||||
|
||||
typedef struct DWTContext {
|
||||
/// line lengths { horizontal, vertical } in consecutive decomposition levels
|
||||
uint16_t linelen[FF_DWT_MAX_DECLVLS][2];
|
||||
int linelen[FF_DWT_MAX_DECLVLS][2];
|
||||
uint8_t mod[FF_DWT_MAX_DECLVLS][2]; ///< coordinates (x0, y0) of decomp. levels mod 2
|
||||
uint8_t ndeclevels; ///< number of decomposition levels
|
||||
uint8_t type; ///< 0 for 9/7; 1 for 5/3
|
||||
@ -57,7 +57,7 @@ typedef struct DWTContext {
|
||||
* @param decomp_levels number of decomposition levels
|
||||
* @param type 0 for DWT 9/7; 1 for DWT 5/3
|
||||
*/
|
||||
int ff_jpeg2000_dwt_init(DWTContext *s, uint16_t border[2][2],
|
||||
int ff_jpeg2000_dwt_init(DWTContext *s, int border[2][2],
|
||||
int decomp_levels, int type);
|
||||
|
||||
int ff_dwt_encode(DWTContext *s, void *t);
|
||||
|
Loading…
x
Reference in New Issue
Block a user