diff --git a/libavcodec/pngdec.c b/libavcodec/pngdec.c index b911c32540..0809d713f1 100644 --- a/libavcodec/pngdec.c +++ b/libavcodec/pngdec.c @@ -567,6 +567,12 @@ static int decode_frame(AVCodecContext *avctx, case MKTAG('I', 'H', 'D', 'R'): if (length != 13) goto fail; + + if (s->state & PNG_IDAT) { + av_log(avctx, AV_LOG_ERROR, "IHDR after IDAT\n"); + goto fail; + } + s->width = bytestream2_get_be32(&s->gb); s->height = bytestream2_get_be32(&s->gb); if(av_image_check_size(s->width, s->height, 0, avctx)){