Hello,
And integer overflow was discovered in Firefox when processing a
crafted webm files [1].
Upstream commits are in [1] as well.
[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1090405
::: content/media/webm/WebMReader.cpp
@@ +668,5 @@
return true;
}
int32_t keepFrames = frames - skipFrames;
+ if (keepFrames < 0) {
+ NS_WARNING("Int overflow in samples");