pictor: Correctly check frame dimensions

Message ID 20171012195019.CAC6A5DBD6@aruru.libav.org
State New
Headers show

Commit Message

Janne Grunau Oct. 12, 2017, 7:50 p.m.
Module: libav
Branch: master
Commit: eb3c1a94adbc28411610167d3dac583436e50125

Author:    Michael Niedermayer <michael@niedermayer.cc>
Committer: Diego Biurrun <diego@biurrun.de>
Date:      Tue Feb  7 15:49:09 2017 +0100

pictor: Correctly check frame dimensions

Fixes: 559/clusterfuzz-testcase-6424225917173760
Bug-Id: CVE-2017-7862
CC: libav-stable@libav.org

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 8c2ea3030af7b40a3c4275696fb5c76cdb80950a)
Signed-off-by: Diego Biurrun <diego@biurrun.de>

---

 libavcodec/pictordec.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Patch

diff --git a/libavcodec/pictordec.c b/libavcodec/pictordec.c
index 9477bc4..49547cf 100644
--- a/libavcodec/pictordec.c
+++ b/libavcodec/pictordec.c
@@ -140,7 +140,7 @@  static int decode_frame(AVCodecContext *avctx,
 
     avctx->pix_fmt = AV_PIX_FMT_PAL8;
 
-    if (s->width != avctx->width && s->height != avctx->height) {
+    if (s->width != avctx->width || s->height != avctx->height) {
         ret = ff_set_dimensions(avctx, s->width, s->height);
         if (ret < 0)
             return ret;