diff options
author | Fraunhofer IIS FDK <audio-fdk@iis.fraunhofer.de> | 2018-11-05 15:14:17 -0800 |
---|---|---|
committer | android-build-merger <android-build-merger@google.com> | 2018-11-05 15:14:17 -0800 |
commit | a16b4cba47a3728fe957ac7eb3f8c227a0d2d87a (patch) | |
tree | dffadfc50eb73efb6bbef80f07856c3c550d54c4 /libAACdec | |
parent | 0404fcb27dc2e4fc6119ec3dd50e023b3a4e4f85 (diff) | |
parent | ac56cddd1f2809aab2acc3b268eb78a3c9467d65 (diff) | |
download | fdk-aac-a16b4cba47a3728fe957ac7eb3f8c227a0d2d87a.tar.gz fdk-aac-a16b4cba47a3728fe957ac7eb3f8c227a0d2d87a.tar.bz2 fdk-aac-a16b4cba47a3728fe957ac7eb3f8c227a0d2d87a.zip |
Merge "Fix huffman decoder escape sequence length limitation." am: a4d6ca7b07
am: ac56cddd1f
Change-Id: I422463f26359bef0ad3220c9324ceb26fcd1da14
Diffstat (limited to 'libAACdec')
-rw-r--r-- | libAACdec/src/block.cpp | 12 |
1 files changed, 7 insertions, 5 deletions
diff --git a/libAACdec/src/block.cpp b/libAACdec/src/block.cpp index 7d2a4b9..b3d09a6 100644 --- a/libAACdec/src/block.cpp +++ b/libAACdec/src/block.cpp @@ -127,9 +127,11 @@ amm-info@iis.fraunhofer.de The function reads the escape sequence from the bitstream, if the absolute value of the quantized coefficient has the value 16. - A limitation is implemented to maximal 31 bits to prevent endless loops. - If it strikes, MAX_QUANTIZED_VALUE + 1 is returned, independent of the sign of - parameter q. + A limitation is implemented to maximal 21 bits according to + ISO/IEC 14496-3:2009(E) 4.6.3.3. + This limits the escape prefix to a maximum of eight 1's. + If more than eight 1's are read, MAX_QUANTIZED_VALUE + 1 is + returned, independent of the sign of parameter q. \return quantized coefficient */ @@ -139,11 +141,11 @@ LONG CBlock_GetEscape(HANDLE_FDK_BITSTREAM bs, /*!< pointer to bitstream */ if (fAbs(q) != 16) return (q); LONG i, off; - for (i = 4; i < 32; i++) { + for (i = 4; i < 13; i++) { if (FDKreadBit(bs) == 0) break; } - if (i == 32) return (MAX_QUANTIZED_VALUE + 1); + if (i == 13) return (MAX_QUANTIZED_VALUE + 1); off = FDKreadBits(bs, i); i = off + (1 << i); |