avformat/mov: fix the check for the heif item parsing loop

Fixes: Null pointer dereference
Fixes: 67861/clusterfuzz-testcase-minimized-ffmpeg_DEMUXER_fuzzer-5352628142800896

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Signed-off-by: James Almer <jamrial@gmail.com>
(cherry picked from commit 31327c2d07)
release/7.0
James Almer 9 months ago
parent 96d941b30e
commit 64a048d4cc
  1. 3
      libavformat/mov.c

@ -9427,7 +9427,8 @@ static int mov_parse_tiles(AVFormatContext *s)
break;
}
if (k == grid->nb_tiles) {
if (k == mov->nb_heif_item) {
av_assert0(loop);
av_log(s, AV_LOG_WARNING, "HEIF item id %d referenced by grid id %d doesn't "
"exist\n",
tile_id, grid->item->item_id);

Loading…
Cancel
Save