Skip to content

[oss-fuzz 3A5166892390350848] Integer-overflow in subtitle_Parse*()

Ref: https://oss-fuzz.com/testcases?q=group%3A5166892390350848

xeon ~/work/git/vlc/build-ubsan $ VLC_TARGET=subtitle ./test/vlc-demux-dec-run /home/tom/Downloads/clusterfuzz-testcase-minimized-vlc-demux-dec-libfuzzer-subtitle-4956019512115200 
../../modules/demux/subtitle.c:1197:31: runtime error: signed integer overflow: 444444441 * 3600 cannot be represented in type 'int'
xeon ~/work/git/vlc/build-ubsan $ VLC_TARGET=subtitle ./test/vlc-demux-dec-run /home/tom/Downloads/clusterfuzz-testcase-minimized-vlc-demux-dec-libfuzzer-subtitle-4956019512115200 
../../modules/demux/subtitle.c:1197:31: runtime error: signed integer overflow: 444444441 * 3600 cannot be represented in type 'int'

Samples:

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information