[FFmpeg-cvslog] avformat/jvdec: clear packet padding after downsize

Michael Niedermayer git at videolan.org
Wed Jan 15 23:31:15 CET 2014


ffmpeg | branch: master | Michael Niedermayer <michaelni at gmx.at> | Wed Jan 15 23:06:30 2014 +0100| [b948ab8132e24d215072120e210139dc456d4997] | committer: Michael Niedermayer

avformat/jvdec: clear packet padding after downsize

Fixes: use of uninitialized memeory
Fixes: msan_uninit-mem_7fbf26b5fefe_5981_intro.jv
Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
Signed-off-by: Michael Niedermayer <michaelni at gmx.at>

> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=b948ab8132e24d215072120e210139dc456d4997
---

 libavformat/jvdec.c |    1 +
 1 file changed, 1 insertion(+)

diff --git a/libavformat/jvdec.c b/libavformat/jvdec.c
index 03ac43d..27ec7ad 100644
--- a/libavformat/jvdec.c
+++ b/libavformat/jvdec.c
@@ -190,6 +190,7 @@ static int read_packet(AVFormatContext *s, AVPacket *pkt)
                 pkt->data[4]      = jvf->video_type;
                 if ((size = avio_read(pb, pkt->data + JV_PREAMBLE_SIZE, size)) < 0)
                     return AVERROR(EIO);
+                memset(pkt->data + JV_PREAMBLE_SIZE + size, 0, FF_INPUT_BUFFER_PADDING_SIZE);
 
                 pkt->size         = size + JV_PREAMBLE_SIZE;
                 pkt->stream_index = 1;



More information about the ffmpeg-cvslog mailing list