Skip to content

[oss-fuzz 42515101] Integer-overflow in MP4_ReadBox_mdhd (libmp4.c)

Ref: https://oss-fuzz.com/testcase-detail/4653891938025472

xeon ~/work/git/vlc/build-ubsan $ ./test/vlc-demux-dec-run /home/tom/Downloads/clusterfuzz-*
../../modules/demux/mp4/libmp4.c:60:36: runtime error: signed integer overflow: 8214576715447232620 * 1000 cannot be represented in type 'long int'

Sample: clusterfuzz-testcase-minimized-vlc-demux-dec-libfuzzer-4653891938025472

Edited by Thomas Guillem
To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information