mirror of
https://mirror.skon.top/https://github.com/FFmpeg/FFmpeg
synced 2026-04-30 13:50:50 +08:00
avcodec/tiff: Check value on positive signed targets
Fixes: CID1604593 Overflowed constant
Sponsored-by: Sovereign Tech Fund
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
(cherry picked from commit 66d6b8033b)
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
This commit is contained in:
@@ -1269,9 +1269,13 @@ static int tiff_decode_tag(TiffContext *s, AVFrame *frame)
|
||||
s->is_thumbnail = (value != 0);
|
||||
break;
|
||||
case TIFF_WIDTH:
|
||||
if (value > INT_MAX)
|
||||
return AVERROR_INVALIDDATA;
|
||||
s->width = value;
|
||||
break;
|
||||
case TIFF_HEIGHT:
|
||||
if (value > INT_MAX)
|
||||
return AVERROR_INVALIDDATA;
|
||||
s->height = value;
|
||||
break;
|
||||
case TIFF_BPP:
|
||||
@@ -1403,12 +1407,18 @@ static int tiff_decode_tag(TiffContext *s, AVFrame *frame)
|
||||
s->tile_byte_counts_offset = off;
|
||||
break;
|
||||
case TIFF_TILE_LENGTH:
|
||||
if (value > INT_MAX)
|
||||
return AVERROR_INVALIDDATA;
|
||||
s->tile_length = value;
|
||||
break;
|
||||
case TIFF_TILE_WIDTH:
|
||||
if (value > INT_MAX)
|
||||
return AVERROR_INVALIDDATA;
|
||||
s->tile_width = value;
|
||||
break;
|
||||
case TIFF_PREDICTOR:
|
||||
if (value > INT_MAX)
|
||||
return AVERROR_INVALIDDATA;
|
||||
s->predictor = value;
|
||||
break;
|
||||
case TIFF_SUB_IFDS:
|
||||
@@ -1539,12 +1549,18 @@ static int tiff_decode_tag(TiffContext *s, AVFrame *frame)
|
||||
}
|
||||
break;
|
||||
case TIFF_T4OPTIONS:
|
||||
if (s->compr == TIFF_G3)
|
||||
if (s->compr == TIFF_G3) {
|
||||
if (value > INT_MAX)
|
||||
return AVERROR_INVALIDDATA;
|
||||
s->fax_opts = value;
|
||||
}
|
||||
break;
|
||||
case TIFF_T6OPTIONS:
|
||||
if (s->compr == TIFF_G4)
|
||||
if (s->compr == TIFF_G4) {
|
||||
if (value > INT_MAX)
|
||||
return AVERROR_INVALIDDATA;
|
||||
s->fax_opts = value;
|
||||
}
|
||||
break;
|
||||
#define ADD_METADATA(count, name, sep)\
|
||||
if ((ret = add_metadata(count, type, name, sep, s, frame)) < 0) {\
|
||||
|
||||
Reference in New Issue
Block a user