[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-commits
Subject:    KDE_3_2_BRANCH: kdegraphics/kpdf/xpdf
From:       Dirk Mueller <mueller () kde ! org>
Date:       2004-10-22 18:08:49
Message-ID: 20041022180849.E055516C2B () office ! kde ! org
[Download RAW message or body]

CVS commit by mueller: 

fixes for integer overflows, patch by Thomas Biege


  M +11 -0     Catalog.cc   1.3.2.1
  M +19 -0     XRef.cc   1.3.2.1


--- kdegraphics/kpdf/xpdf/Catalog.cc  #1.3:1.3.2.1
@@ -64,4 +64,10 @@ Catalog::Catalog(XRef *xrefA) {
   pagesSize = numPages0 = obj.getInt();
   obj.free();
+  if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
+      pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
+    error(-1, "Invalid 'pagesSize'");
+    ok = gFalse;
+    return;
+  }
   pages = (Page **)gmalloc(pagesSize * sizeof(Page *));
   pageRefs = (Ref *)gmalloc(pagesSize * sizeof(Ref));
@@ -191,4 +197,9 @@ int Catalog::readPageTree(Dict *pagesDic
       if (start >= pagesSize) {
         pagesSize += 32;
+        if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
+            pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
+          error(-1, "Invalid 'pagesSize' parameter.");
+          goto err3;
+        }
         pages = (Page **)grealloc(pages, pagesSize * sizeof(Page *));
         pageRefs = (Ref *)grealloc(pageRefs, pagesSize * sizeof(Ref));

--- kdegraphics/kpdf/xpdf/XRef.cc  #1.3:1.3.2.1
@@ -77,4 +77,10 @@ XRef::XRef(BaseStream *strA, GString *ow
   // trailer is ok - read the xref table
   } else {
+    if (size*sizeof(XRefEntry)/sizeof(XRefEntry) != size) {
+      error(-1, "Invalid 'size' inside xref table.");
+      ok = gFalse;
+      errCode = errDamaged;
+      return;
+    }
     entries = (XRefEntry *)gmalloc(size * sizeof(XRefEntry));
     for (i = 0; i < size; ++i) {
@@ -268,4 +274,8 @@ GBool XRef::readXRef(Guint *pos) {
     if (first + n > size) {
       newSize = size + 256;
+      if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
+        error(-1, "Invalid 'newSize'");
+        goto err2;
+      }
       entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry));
       for (i = size; i < newSize; ++i) {
@@ -416,4 +426,8 @@ GBool XRef::constructXRef() {
               if (num >= size) {
                 newSize = (num + 1 + 255) & ~255;
+                if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
+                  error(-1, "Invalid 'obj' parameters.");
+                  return gFalse;
+                }
                 entries = (XRefEntry *)
                             grealloc(entries, newSize * sizeof(XRefEntry));
@@ -437,4 +451,9 @@ GBool XRef::constructXRef() {
       if (streamEndsLen == streamEndsSize) {
         streamEndsSize += 64;
+        if (streamEndsSize*sizeof(int)/sizeof(int) != streamEndsSize) {
+          error(-1, "Invalid 'endstream' parameter.");
+          return gFalse;
+        }
+
         streamEnds = (Guint *)grealloc(streamEnds,
                                        streamEndsSize * sizeof(int));


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic