avcodec/dsicinvideo: Fail if there is only a small fraction of the data available that comprises a full frame

Fixes: Timeout
Fixes: 6306/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_DSICINVIDEO_fuzzer-5079253549842432

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
pull/298/head
Michael Niedermayer 7 years ago
parent 942217b153
commit 5549488bbf
  1. 7
      libavcodec/dsicinvideo.c

@ -158,6 +158,9 @@ static int cin_decode_lzss(const unsigned char *src, int src_size,
} }
} }
if (dst_end - dst > dst_size - dst_size/10)
return AVERROR_INVALIDDATA;
return 0; return 0;
} }
@ -184,6 +187,10 @@ static int cin_decode_rle(const unsigned char *src, int src_size,
} }
dst += len; dst += len;
} }
if (dst_end - dst > dst_size - dst_size/10)
return AVERROR_INVALIDDATA;
return 0; return 0;
} }

Loading…
Cancel
Save