pictor: Correctly check frame dimensions
authorMichael Niedermayer <michael@niedermayer.cc>
Tue, 7 Feb 2017 14:49:09 +0000 (15:49 +0100)
committerDiego Biurrun <diego@biurrun.de>
Thu, 12 Oct 2017 19:20:05 +0000 (21:20 +0200)
Fixes: 559/clusterfuzz-testcase-6424225917173760
Bug-Id: CVE-2017-7862
CC: libav-stable@libav.org
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/targets/ffmpeg
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 8c2ea3030af7b40a3c4275696fb5c76cdb80950a)
Signed-off-by: Diego Biurrun <diego@biurrun.de>
libavcodec/pictordec.c

index 9477bc4..49547cf 100644 (file)
@@ -140,7 +140,7 @@ static int decode_frame(AVCodecContext *avctx,
 
     avctx->pix_fmt = AV_PIX_FMT_PAL8;
 
-    if (s->width != avctx->width && s->height != avctx->height) {
+    if (s->width != avctx->width || s->height != avctx->height) {
         ret = ff_set_dimensions(avctx, s->width, s->height);
         if (ret < 0)
             return ret;