Michael Niedermayer
e3368b7f82
avcodec/dvbsubdec: check region dimensions
...
Fixes: 1408/clusterfuzz-testcase-minimized-6529985844084736
Fixes: integer overflow
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 0075d9eced
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:23 +02:00
Michael Niedermayer
34a7677f29
avcodec/vp8dsp: Fixes: runtime error: signed integer overflow: 1330143360 - -1023040530 cannot be represented in type 'int'
...
Fixes: 1406/clusterfuzz-testcase-minimized-5064865125236736
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 8824b7370a
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:23 +02:00
Michael Niedermayer
45763713e8
avcodec/hqxdsp: Fix multiple runtime error: signed integer overflow: 248220 * 21407 cannot be represented in type 'int' in idct_col()
...
Fixes: 1405/clusterfuzz-testcase-minimized-5011491835084800
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 5d5118f81b
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:23 +02:00
Michael Niedermayer
7e5ece1052
avcodec/cavsdec: Check sym_factor
...
Fixes: runtime error: signed integer overflow: 25984 * 130560 cannot be represented in type 'int'
Fixes: 1404/clusterfuzz-testcase-minimized-5000441286885376
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 279420b5a6
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:23 +02:00
Michael Niedermayer
4f98b97b2a
avcodec/cdxl: Check format for BGR24
...
Fixes: out of array access
Fixes: 1427/clusterfuzz-testcase-minimized-5020737339392000
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 1e42736b95
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:23 +02:00
Michael Niedermayer
782473f9df
avcodec/ffv1dec: Fix copying planes of paletted formats
...
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 3a4d387195
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:23 +02:00
Michael Niedermayer
be531b4762
avcodec/wmv2dsp: Fix runtime error: signed integer overflow: 181 * -12156865 cannot be represented in type 'int'
...
Fixes: 1401/clusterfuzz-testcase-minimized-6526248148795392
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 8b1f66cf5c
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
e2103ad36d
avcodec/xwddec: Check bpp more completely
...
Fixes out of array access
Fixes: 1399/clusterfuzz-testcase-minimized-4866094172995584
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 441026fcb1
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
71a568e47d
avcodec/s302m: Fix left shift of 8 by 28 places cannot be represented in type 'int'
...
Fixes: 1395/clusterfuzz-testcase-minimized-5330939741732864
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit a38e9797cb
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
aab7b9e6bc
avcodec/eamad: Fix runtime error: signed integer overflow: 49674 * 49858 cannot be represented in type 'int'
...
Fixes: 1394/clusterfuzz-testcase-minimized-6493376885030912
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 0ac1c87194
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
93f9d9dc6c
avcodec/g726: Fix runtime error: left shift of negative value -2
...
Fixes: 1393/clusterfuzz-testcase-minimized-5948366791901184
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit c04aa14882
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
b0f57bd326
avcodec/ra144: Fix runtime error: left shift of negative value -798
...
Fixes: 1388/clusterfuzz-testcase-minimized-6680800936329216
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 78bf446852
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
a11e5577a2
avcodec/mss34dsp: Fix multiple signed integer overflow
...
Fixes: 1387/clusterfuzz-testcase-minimized-4802757766676480
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 464c4b86ee
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
23853514e5
avcodec/targa_y216dec: Fix width type
...
Fixes out of array access
Fixes: 1376/clusterfuzz-testcase-minimized-6361794975105024
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 3e56db8926
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
b892a0b1c0
avcodec/texturedsp: Fix multiple runtime error: left shift of 255 by 24 places cannot be represented in type 'int'
...
Fixes: 1386/clusterfuzz-testcase-minimized-5323086394032128
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit e92fb2bea1
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
d9faa9bd63
avcodec/ivi_dsp: Fix multiple left shift of negative value -2
...
Fixes: 1385/clusterfuzz-testcase-minimized-5552882663292928
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 9e88cc94e5
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
ef40a32dbb
avcodec/svq3: Fix multiple runtime error: signed integer overflow: 44161 * 61694 cannot be represented in type 'int'
...
Fixes: 1382/clusterfuzz-testcase-minimized-6013445293998080
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 669419939c
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
8464f25089
avcodec/msmpeg4dec: Correct table depth
...
Fixes undefined shift
Fixes: 1381/clusterfuzz-testcase-minimized-5513944540119040
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 1121d92707
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
47e2c70dcd
avcodec/dds: Fix runtime error: left shift of 1 by 31 places cannot be represented in type 'int'
...
Fixes: 1380/clusterfuzz-testcase-minimized-650122545122508
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 8a8335de03
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
94029d7e17
avcodec/cdxl: Check format parameter
...
Fixes out of array access
Fixes: 1378/clusterfuzz-testcase-minimized-5715088008806400
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit e1b60aad77
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
54eaa109ed
avutil/softfloat: Fix overflow in av_div_sf()
...
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 277e397eb5
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
78b47e9229
avcodec/hq_hqa: Fix runtime error: left shift of negative value -207
...
Fixes: 1375/clusterfuzz-testcase-minimized-6070134701555712
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 1283c42447
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
cbd8be63cf
avcodec/mss3: Change types in rac_get_model_sym() to match the types they are initialized from
...
Fixes integer overflow
Fixes: 1372/clusterfuzz-testcase-minimized-5712192982745088
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 2ef0f39271
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
22de9c949a
avcodec/shorten: Check k in get_uint()
...
Fixes: undefined shift
Fixes: 1371/clusterfuzz-testcase-minimized-5770822591447040
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 7b6a51f59c
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
5578f63494
avcodec/webp: Fix null pointer dereference
...
Fixes: 1369/clusterfuzz-testcase-minimized-5048908029886464
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 9bf4523e40
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
2c7e4e5e71
avcodec/dfa: Fix signed integer overflow: -2147483648 - 1 cannot be represented in type 'int'
...
Fixes: 1368/clusterfuzz-testcase-minimized-4507293276176384
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 12936a4585
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
677c9f27cc
avcodec/g723_1: Fix multiple runtime error: left shift of negative value
...
Fixes: 1367/clusterfuzz-testcase-minimized-571496882346393
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 4ace2d2219
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
9f7bc8296b
avcodec/mimic: Fix runtime error: left shift of negative value -1
...
Fixes: 1365/clusterfuzz-testcase-minimized-5624158450876416
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit fc2c420b82
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
ceb456e3e9
avcodec/fic: Fix multiple left shift of negative value -15
...
Fixes: 1356/clusterfuzz-testcase-minimized-6008489086287872
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit b20c71409b
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
23a76f1057
avcodec/mlpdec: Fix runtime error: left shift of negative value -22
...
Fixes: 1355/clusterfuzz-testcase-minimized-6662205472768000
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit c535436cbe
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
e7755214bb
avcodec/snowdec: Check qbias
...
Fixes: signed integer overflow: -1094995529 * 131 cannot be represented in type 'int'
Fixes: 1353/clusterfuzz-testcase-minimized-5208180449607680
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 523205ce1e
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
1fe0de8934
avutil/softfloat: Fix multiple runtime error: left shift of negative value -8
...
Fixes: 1352/clusterfuzz-testcase-minimized-5757565017260032
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 35f3df0d76
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
fb4a81dc3a
avcodec/aacsbr_template: Do not leave bs_num_env invalid
...
Fixes out of array read
Fixes: 1349/clusterfuzz-testcase-minimized-5370707196248064
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit a8ad83b793
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
0924491799
avcodec/mdec: Fix signed integer overflow: 28835400 * 83 cannot be represented in type 'int'
...
Fixes: 1346/clusterfuzz-testcase-minimized-5776732600664064
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit a234b5ade3
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
eb234fa89b
avcodec/dfa: Fix off by 1 error
...
Fixes out of array access
Fixes: 1345/clusterfuzz-testcase-minimized-6062963045695488
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit f52fbf4f3e
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
e01f028949
avcodec/nellymoser: Fix multiple left shift of negative value -8591
...
Fixes: 1342/clusterfuzz-testcase-minimized-5490842129137664
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 0953736b7e
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
dd907bec36
avcodec/cdxl: Fix signed integer overflow: 14243456 * 164 cannot be represented in type 'int'
...
Fixes: 1341/clusterfuzz-testcase-minimized-5441502618583040
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 1002932a3b
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
4547015097
avcodec/g722: Fix multiple runtime error: left shift of negative value -1
...
Fixes: 1340/clusterfuzz-testcase-minimized-4669892148068352
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit f55df62998
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
ba0081fbbe
avcodec/dss_sp: Fix multiple left shift of negative value -466
...
Fixes: 1339/clusterfuzz-testcase-minimized-4614671485108224
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 38152d9368
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
0eb229a427
avcodec/wnv1: Fix runtime error: left shift of negative value -1
...
Fixes: 1338/clusterfuzz-testcase-minimized-6485546354343936
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 9fac508ca4
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
6756196994
avcodec/tiertexseqv: set the fixed dimenasions, do not depend on the demuxer doing so
...
Fixes: out of array access
Fixes: 1348/clusterfuzz-testcase-minimized-6195673642827776
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit ce551a3925
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
ac74ac9e1d
avcodec/mjpegdec: Fix runtime error: signed integer overflow: -24543 * 2031616 cannot be represented in type 'int'
...
Fixes: 943/clusterfuzz-testcase-5114865297391616
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit a78ae465fd
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
a6fb07d5ba
avcodec/cavsdec: Fix undefined behavior from integer overflow
...
Fixes: 1335/clusterfuzz-testcase-minimized-5566961566089216
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit a0e5f7f363
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
cc9b7db429
avcodec/dvdsubdec: Fix runtime error: left shift of 242 by 24 places cannot be represented in type 'int'
...
Fixes: 1080/clusterfuzz-testcase-5353236754071552
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit ce7098b8f2
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
cbc471d1b3
libavcodec/mpeg4videodec: Convert sprite_offset to 64bit
...
This avoids intermediates from overflowing (the final values are checked)
Fixes: runtime error: signed integer overflow: -167712 + -2147352576 cannot be represented in type 'int'
Fixes: 1298/clusterfuzz-testcase-minimized-5955580877340672
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit c1c3a14073
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
55d8fd38d6
avcodec/pngdec: Use ff_set_dimensions()
...
Fixes OOM
Fixes: 1314/clusterfuzz-testcase-minimized-4621997222920192
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit a0296fc056
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
d4f008557a
avcodec/msvideo1: Check buffer size before re-getting the frame
...
Fixes timeout
Fixes: 1306/clusterfuzz-testcase-minimized-6152296217968640
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit cabfed6895
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
6798f9c551
avcodec/h264_cavlc: Fix undefined behavior on qscale overflow
...
Fixes: 1214/clusterfuzz-testcase-minimized-6130606599569408
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit fc8cff96ed
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
cfc85cead9
avcodec/dcadsp: Fix runtime error: signed integer overflow
...
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 9244b839b7
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00
Michael Niedermayer
2cfd230759
avcodec/svq3: Reject dx/dy beyond 16bit
...
The code does use 16bit sized arrays later so larger deltas would not work
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
(cherry picked from commit 48b3117844
)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc >
2017-05-16 16:00:22 +02:00