On Wed, Jan 13, 2016 at 5:53 PM, Michael Niedermayer <g...@videolan.org> wrote:
> ffmpeg | branch: master | Michael Niedermayer <mich...@niedermayer.cc> | Wed 
> Jan 13 22:33:59 2016 +0100| [92465a2347d959cbd9864b017a39b2a4ab9313ff] | 
> committer: Michael Niedermayer
>
> avcodec/aacenc: Check for +-Inf too
>
> Fixes out of array read
> Fixes: 
> 04442da73d935b776d2236282588d4f9/signal_sigsegv_2625a69_8790_ae85ffc889070663319b3417ede777b0.mov
>
> Found-by: Mateusz "j00ru" Jurczyk and Gynvael Coldwind
> Signed-off-by: Michael Niedermayer <mich...@niedermayer.cc>
>
>> http://git.videolan.org/gitweb.cgi/ffmpeg.git/?a=commit;h=92465a2347d959cbd9864b017a39b2a4ab9313ff
> ---
>
>  libavcodec/aacenc.c |   18 +++++++++---------
>  1 file changed, 9 insertions(+), 9 deletions(-)
>
> diff --git a/libavcodec/aacenc.c b/libavcodec/aacenc.c
> index 2a3fc6e..9a7d3a8 100644
> --- a/libavcodec/aacenc.c
> +++ b/libavcodec/aacenc.c
> @@ -606,16 +606,16 @@ static int aac_encode_frame(AVCodecContext *avctx, 
> AVPacket *avpkt,
>                  s->mdct1024.mdct_calc(&s->mdct1024, sce->lcoeffs, 
> sce->ret_buf);
>              }
>
> -            if (isnan(cpe->ch->coeffs[0]) ||
> -                isnan(cpe->ch->coeffs[  128]) ||
> -                isnan(cpe->ch->coeffs[2*128]) ||
> -                isnan(cpe->ch->coeffs[3*128]) ||
> -                isnan(cpe->ch->coeffs[4*128]) ||
> -                isnan(cpe->ch->coeffs[5*128]) ||
> -                isnan(cpe->ch->coeffs[6*128]) ||
> -                isnan(cpe->ch->coeffs[7*128])
> +            if (isnan(cpe->ch->coeffs[    0]) || isinf(cpe->ch->coeffs[    
> 0]) ||
> +                isnan(cpe->ch->coeffs[  128]) || isinf(cpe->ch->coeffs[  
> 128]) ||
> +                isnan(cpe->ch->coeffs[2*128]) || 
> isinf(cpe->ch->coeffs[2*128]) ||
> +                isnan(cpe->ch->coeffs[3*128]) || 
> isinf(cpe->ch->coeffs[3*128]) ||
> +                isnan(cpe->ch->coeffs[4*128]) || 
> isinf(cpe->ch->coeffs[4*128]) ||
> +                isnan(cpe->ch->coeffs[5*128]) || 
> isinf(cpe->ch->coeffs[5*128]) ||
> +                isnan(cpe->ch->coeffs[6*128]) || 
> isinf(cpe->ch->coeffs[6*128]) ||
> +                isnan(cpe->ch->coeffs[7*128]) || 
> isinf(cpe->ch->coeffs[7*128])

A cleaner solution would be to do a !isfinite. As usual, msvc stops
the whole show, so someone can add a trivial fallback, e.g isfinite =
!(isnan || isinf).

>              ) {
> -                av_log(avctx, AV_LOG_ERROR, "Input contains NaN\n");
> +                av_log(avctx, AV_LOG_ERROR, "Input contains NaN/+-Inf\n");
>                  return AVERROR(EINVAL);
>              }
>              avoid_clipping(s, sce);
>
> _______________________________________________
> ffmpeg-cvslog mailing list
> ffmpeg-cvslog@ffmpeg.org
> http://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog
_______________________________________________
ffmpeg-cvslog mailing list
ffmpeg-cvslog@ffmpeg.org
http://ffmpeg.org/mailman/listinfo/ffmpeg-cvslog

Reply via email to