pictor: Correctly check frame dimensions
authorMichael Niedermayer <michael@niedermayer.cc>
Tue, 7 Feb 2017 14:49:09 +0000 (15:49 +0100)
committerDiego Biurrun <diego@biurrun.de>
Wed, 11 Oct 2017 20:56:27 +0000 (22:56 +0200)
Fixes: 559/clusterfuzz-testcase-6424225917173760
Bug-Id: CVE-2017-7862

Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 8c2ea3030af7b40a3c4275696fb5c76cdb80950a)
Signed-off-by: Diego Biurrun <diego@biurrun.de>
libavcodec/pictordec.c

index 6f2193d..5203041 100644 (file)
@@ -138,7 +138,7 @@ static int decode_frame(AVCodecContext *avctx,
 
     avctx->pix_fmt = PIX_FMT_PAL8;
 
-    if (s->width != avctx->width && s->height != avctx->height) {
+    if (s->width != avctx->width || s->height != avctx->height) {
         if (av_image_check_size(s->width, s->height, 0, avctx) < 0)
             return -1;
         avcodec_set_dimensions(avctx, s->width, s->height);