qdm2: clip array indices returned by qdm2_get_vlc().
Prevents subsequent overreads when these numbers are used as indices in arrays. Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind CC: libav-stable@libav.org Signed-off-by: Justin Ruggles <justin.ruggles@gmail.com> (cherry picked from commit 64953f67f98da2e787aeb45cc7f504390fa32a69) Signed-off-by: Derek Buitenhuis <derek.buitenhuis@gmail.com> Conflicts: libavcodec/qdm2.c
This commit is contained in:
parent
07bff95176
commit
4bccd5a36b
@ -883,9 +883,13 @@ static void synthfilt_build_sb_samples (QDM2Context *q, GetBitContext *gb, int l
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
case 30:
|
case 30:
|
||||||
if (BITS_LEFT(length,gb) >= 4)
|
if (BITS_LEFT(length,gb) >= 4) {
|
||||||
samples[0] = type30_dequant[qdm2_get_vlc(gb, &vlc_tab_type30, 0, 1)];
|
unsigned index = qdm2_get_vlc(gb, &vlc_tab_type30, 0, 1);
|
||||||
else
|
if (index < FF_ARRAY_ELEMS(type30_dequant)) {
|
||||||
|
samples[0] = type30_dequant[index];
|
||||||
|
} else
|
||||||
|
samples[0] = SB_DITHERING_NOISE(sb,q->noise_idx);
|
||||||
|
} else
|
||||||
samples[0] = SB_DITHERING_NOISE(sb,q->noise_idx);
|
samples[0] = SB_DITHERING_NOISE(sb,q->noise_idx);
|
||||||
|
|
||||||
run = 1;
|
run = 1;
|
||||||
@ -899,8 +903,12 @@ static void synthfilt_build_sb_samples (QDM2Context *q, GetBitContext *gb, int l
|
|||||||
type34_predictor = samples[0];
|
type34_predictor = samples[0];
|
||||||
type34_first = 0;
|
type34_first = 0;
|
||||||
} else {
|
} else {
|
||||||
samples[0] = type34_delta[qdm2_get_vlc(gb, &vlc_tab_type34, 0, 1)] / type34_div + type34_predictor;
|
unsigned index = qdm2_get_vlc(gb, &vlc_tab_type34, 0, 1);
|
||||||
type34_predictor = samples[0];
|
if (index < FF_ARRAY_ELEMS(type34_delta)) {
|
||||||
|
samples[0] = type34_delta[index] / type34_div + type34_predictor;
|
||||||
|
type34_predictor = samples[0];
|
||||||
|
} else
|
||||||
|
samples[0] = SB_DITHERING_NOISE(sb,q->noise_idx);
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
samples[0] = SB_DITHERING_NOISE(sb,q->noise_idx);
|
samples[0] = SB_DITHERING_NOISE(sb,q->noise_idx);
|
||||||
|
Loading…
x
Reference in New Issue
Block a user