diff options
author | Daniel Baumann <daniel.baumann@progress-linux.org> | 2024-04-07 09:22:09 +0000 |
---|---|---|
committer | Daniel Baumann <daniel.baumann@progress-linux.org> | 2024-04-07 09:22:09 +0000 |
commit | 43a97878ce14b72f0981164f87f2e35e14151312 (patch) | |
tree | 620249daf56c0258faa40cbdcf9cfba06de2a846 /media/libogg/ogg-fuzzing.patch | |
parent | Initial commit. (diff) | |
download | firefox-upstream.tar.xz firefox-upstream.zip |
Adding upstream version 110.0.1.upstream/110.0.1upstream
Signed-off-by: Daniel Baumann <daniel.baumann@progress-linux.org>
Diffstat (limited to 'media/libogg/ogg-fuzzing.patch')
-rw-r--r-- | media/libogg/ogg-fuzzing.patch | 50 |
1 files changed, 50 insertions, 0 deletions
diff --git a/media/libogg/ogg-fuzzing.patch b/media/libogg/ogg-fuzzing.patch new file mode 100644 index 0000000000..c09b6e86b0 --- /dev/null +++ b/media/libogg/ogg-fuzzing.patch @@ -0,0 +1,50 @@ +# HG changeset patch +# User Christian Holler <choller@mozilla.com> +# Date 1561460220 -7200 +# Tue Jun 25 12:57:00 2019 +0200 +# Node ID 063a710e0bd70855ed5342ce109d42ea3b1a4abf +# Parent 2388cab0a545d744bd109fa3a7af3b22a3dc4ced +Bug 1561256 - Disable CRC checks in ogg framing for FUZZING. r=drno + +diff --git a/media/libogg/src/ogg_framing.c b/media/libogg/src/ogg_framing.c +--- a/media/libogg/src/ogg_framing.c ++++ b/media/libogg/src/ogg_framing.c +@@ -287,34 +287,38 @@ static int _os_lacing_expand(ogg_stream_ + } + + /* checksum the page */ + /* Direct table CRC; note that this will be faster in the future if we + perform the checksum simultaneously with other copies */ + + void ogg_page_checksum_set(ogg_page *og){ + if(og){ ++#ifndef FUZZING + ogg_uint32_t crc_reg=0; + int i; ++#endif + + /* safety; needed for API behavior, but not framing code */ + og->header[22]=0; + og->header[23]=0; + og->header[24]=0; + og->header[25]=0; + ++#ifndef FUZZING + for(i=0;i<og->header_len;i++) + crc_reg=(crc_reg<<8)^crc_lookup[((crc_reg >> 24)&0xff)^og->header[i]]; + for(i=0;i<og->body_len;i++) + crc_reg=(crc_reg<<8)^crc_lookup[((crc_reg >> 24)&0xff)^og->body[i]]; + + og->header[22]=(unsigned char)(crc_reg&0xff); + og->header[23]=(unsigned char)((crc_reg>>8)&0xff); + og->header[24]=(unsigned char)((crc_reg>>16)&0xff); + og->header[25]=(unsigned char)((crc_reg>>24)&0xff); ++#endif + } + } + + /* submit data to the internal buffer of the framing engine */ + int ogg_stream_iovecin(ogg_stream_state *os, ogg_iovec_t *iov, int count, + long e_o_s, ogg_int64_t granulepos){ + + long bytes = 0, lacing_vals; |