[libav-bugs] [Bug 1136] New: One null pointer deference in ff_vc1_parse_frame_header_adv in vc1.c

bugzilla at libav.org bugzilla at libav.org
Mon Oct 29 02:29:17 CET 2018


https://bugzilla.libav.org/show_bug.cgi?id=1136

            Bug ID: 1136
           Summary: One null pointer deference  in
                    ff_vc1_parse_frame_header_adv in vc1.c
           Product: Libav
           Version: 12
          Hardware: X86
                OS: Linux
            Status: NEW
          Severity: normal
          Priority: ---
         Component: libavcodec
          Assignee: bugzilla at libav.org
          Reporter: 92wyunchao at gmail.com

Created attachment 721
  --> https://bugzilla.libav.org/attachment.cgi?id=721&action=edit
poc to reproduce the crash

$uname -a
Linux VM-0-9-ubuntu 4.4.0-91-generic #114-Ubuntu SMP Tue Aug 8 11:56:56 UTC
2017 x86_64 x86_64 x86_64 GNU/Linux

$ASAN_OPTIONS=halt_on_error=false:allow_addr2line=true ./avconv -i poc -f null
-

ASAN:DEADLYSIGNAL
=================================================================
==16226==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc
0x0000016cf62c bp 0x7ffe63ae38d0 sp 0x7ffe63ae32e0 T0)
    #0 0x16cf62b in ff_vc1_parse_frame_header_adv
/home/ubuntu/asan/libav-12.3/libavcodec/vc1.c:848
    #1 0x177f7a0 in vc1_decode_frame
/home/ubuntu/asan/libav-12.3/libavcodec/vc1dec.c:762
    #2 0x16950f7 in avcodec_decode_video2
/home/ubuntu/asan/libav-12.3/libavcodec/utils.c:1588
    #3 0x1697c5b in do_decode
/home/ubuntu/asan/libav-12.3/libavcodec/utils.c:1727
    #4 0x16978b6 in avcodec_send_packet
/home/ubuntu/asan/libav-12.3/libavcodec/utils.c:1804
    #5 0x532ad1 in decode /home/ubuntu/asan/libav-12.3/avconv.c:1295
    #6 0x532ad1 in decode_video /home/ubuntu/asan/libav-12.3/avconv.c:1395
    #7 0x532ad1 in process_input_packet
/home/ubuntu/asan/libav-12.3/avconv.c:1514
    #8 0x52848d in process_input /home/ubuntu/asan/libav-12.3/avconv.c:2690
    #9 0x52848d in transcode /home/ubuntu/asan/libav-12.3/avconv.c:2732
    #10 0x52848d in main /home/ubuntu/asan/libav-12.3/avconv.c:2905
    #11 0x7f2636e2282f in __libc_start_main
/build/glibc-Cl5G7W/glibc-2.23/csu/../csu/libc-start.c:291
    #12 0x41a888 in _start (/home/ubuntu/asan/libav-12.3/avconv+0x41a888)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV
/home/ubuntu/asan/libav-12.3/libavcodec/vc1.c:848 in
ff_vc1_parse_frame_header_adv
==16226==ABORTING

-- 
You are receiving this mail because:
You are watching all bug changes.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.libav.org/pipermail/libav-bugs/attachments/20181029/9fde8475/attachment-0001.html>


More information about the libav-bugs mailing list