diff options
author | Michael Niedermayer <michael@niedermayer.cc> | 2019-08-31 00:03:57 +0200 |
---|---|---|
committer | Michael Niedermayer <michael@niedermayer.cc> | 2019-08-31 17:33:56 +0200 |
commit | a370582ba9c4e0db4e8518d4df199003d36bea16 (patch) | |
tree | e70d9179932f4b748f85a1a0e06ae92b214c1ef0 /tools | |
parent | c79d6728a75528b7fa77035b089b456a953b8e3f (diff) | |
download | ffmpeg-a370582ba9c4e0db4e8518d4df199003d36bea16.tar.gz |
tools/target_dec_fuzzer: Init parsepkt
Fixes: memory corruption
Fixes: 16702/clusterfuzz-testcase-minimized-ffmpeg_AV_CODEC_ID_PNG_fuzzer-5768418552184832
Found-by: continuous fuzzing process https://github.com/google/oss-fuzz/tree/master/projects/ffmpeg
Reviewed-by: James Almer <jamrial@gmail.com>
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
Diffstat (limited to 'tools')
-rw-r--r-- | tools/target_dec_fuzzer.c | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/tools/target_dec_fuzzer.c b/tools/target_dec_fuzzer.c index e22a0c5c34..901dbca385 100644 --- a/tools/target_dec_fuzzer.c +++ b/tools/target_dec_fuzzer.c @@ -194,6 +194,7 @@ int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size) { // Read very simple container AVPacket avpkt, parsepkt; av_init_packet(&avpkt); + av_init_packet(&parsepkt); while (data < end && it < maxiteration) { // Search for the TAG while (data + sizeof(fuzz_tag) < end) { |