Browse Source

avformat/swfdec: clear 4 bytes at the end of a packet if they are not initialized

Fixes use of uninitialized memory
Fixes part of msan_uninit-mem_7f055dd0ab1b_9558_videopop_guitar_300k.swf
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
tags/n2.2-rc1
Michael Niedermayer 11 years ago
parent
commit
f5d039840a
1 changed files with 1 additions and 0 deletions
  1. +1
    -0
      libavformat/swfdec.c

+ 1
- 0
libavformat/swfdec.c View File

@@ -455,6 +455,7 @@ bitmap_end_skip:
/* old SWF files containing SOI/EOI as data start */
/* files created by swink have reversed tag */
pkt->size -= 4;
memset(pkt->data+pkt->size, 0, 4);
res = avio_read(pb, pkt->data, pkt->size);
} else {
res = avio_read(pb, pkt->data + 4, pkt->size - 4);


Loading…
Cancel
Save