Fix is similar to rac_get_model_sym()
Fixes: 1483/clusterfuzz-testcase-minimized-
6386507814273024
Fixes: 1485/clusterfuzz-testcase-minimized-
6639880215986176
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
static int rac_get_model256_sym(RangeCoder *c, Model256 *m)
{
- int prob, prob2, helper, val;
+ int val;
int start, end;
int ssym;
+ unsigned prob, prob2, helper;
prob2 = c->range;
c->range >>= MODEL_SCALE;