Browse Source

avformat/pva: Make sure the header is large enough before reading the timestamp from it

Fixes use of uninitialized memory
Fixes: msan_uninit-mem_7f34b5dc6d58_2674_PVA_test-partial.pva
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
tags/n2.2-rc1
Michael Niedermayer 12 years ago
parent
commit
eedd914873
1 changed files with 7 additions and 1 deletions
  1. +7
    -1
      libavformat/pva.c

+ 7
- 1
libavformat/pva.c View File

@@ -152,8 +152,14 @@ recover:


pvactx->continue_pes = pes_packet_length; pvactx->continue_pes = pes_packet_length;


if (pes_flags & 0x80 && (pes_header_data[0] & 0xf0) == 0x20)
if (pes_flags & 0x80 && (pes_header_data[0] & 0xf0) == 0x20) {
if (pes_header_data_length < 5) {
pva_log(s, AV_LOG_ERROR, "header too short\n");
avio_skip(pb, length);
return AVERROR_INVALIDDATA;
}
pva_pts = ff_parse_pes_pts(pes_header_data); pva_pts = ff_parse_pes_pts(pes_header_data);
}
} }


pvactx->continue_pes -= length; pvactx->continue_pes -= length;


Loading…
Cancel
Save