diff options
| author | trylab <trylab@users.noreply.github.com> | 2016-09-06 13:55:49 +0800 |
|---|---|---|
| committer | Matthieu Darbois <mayeut@users.noreply.github.com> | 2016-09-06 07:55:49 +0200 |
| commit | c16bc057ba3f125051c9966cf1f5b68a05681de4 (patch) | |
| tree | 4275b724248681a427da9b0703561deff7d03a15 /src/lib/openjp2 | |
| parent | ea320dab8bc491c10b1584a6617378cecea9f4fa (diff) | |
Fix an integer overflow issue (#809)
Prevent an integer overflow issue in function opj_pi_create_decode of
pi.c.
Diffstat (limited to 'src/lib/openjp2')
| -rw-r--r-- | src/lib/openjp2/pi.c | 8 |
1 files changed, 7 insertions, 1 deletions
diff --git a/src/lib/openjp2/pi.c b/src/lib/openjp2/pi.c index cffad668..36e2ff0c 100644 --- a/src/lib/openjp2/pi.c +++ b/src/lib/openjp2/pi.c @@ -1237,7 +1237,13 @@ opj_pi_iterator_t *opj_pi_create_decode(opj_image_t *p_image, l_current_pi = l_pi; /* memory allocation for include */ - l_current_pi->include = (OPJ_INT16*) opj_calloc((l_tcp->numlayers +1) * l_step_l, sizeof(OPJ_INT16)); + /* prevent an integer overflow issue */ + l_current_pi->include = 00; + if (l_step_l <= (SIZE_MAX / (l_tcp->numlayers + 1U))) + { + l_current_pi->include = (OPJ_INT16*) opj_calloc((l_tcp->numlayers +1) * l_step_l, sizeof(OPJ_INT16)); + } + if (!l_current_pi->include) { |
