OSDN Git Service

avcodec/gifdec: check that the correct number of bytes was decoded
authorMichael Niedermayer <michaelni@gmx.at>
Tue, 17 Dec 2013 01:32:19 +0000 (02:32 +0100)
committerMichael Niedermayer <michaelni@gmx.at>
Tue, 17 Dec 2013 01:33:19 +0000 (02:33 +0100)
Fixes use of uninitialized memory
Fixes: msan_uninit-mem_7f084c646637_9261_top_title_green_frog.gif
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: Michael Niedermayer <michaelni@gmx.at>
libavcodec/gifdec.c

index c7b9ac8..78c8900 100644 (file)
@@ -237,8 +237,12 @@ static int gif_read_image(GifState *s, AVFrame *frame)
     pass = 0;
     y1 = 0;
     for (y = 0; y < height; y++) {
-        if (ff_lzw_decode(s->lzw, s->idx_line, width) == 0)
+        int count = ff_lzw_decode(s->lzw, s->idx_line, width);
+        if (count != width) {
+            if (count)
+                av_log(s->avctx, AV_LOG_ERROR, "LZW decode failed\n");
             goto decode_tail;
+        }
 
         pr = ptr + width;