File: 04-gif-read-errors.patch

package info (click to toggle)
xmahjongg 3.7-5
  • links: PTS, VCS
  • area: main
  • in suites: bookworm, bullseye
  • size: 2,796 kB
  • sloc: cpp: 7,461; ansic: 3,606; sh: 784; makefile: 146
file content (155 lines) | stat: -rw-r--r-- 4,044 bytes parent folder | download | duplicates (4)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
Teach the GIF library about read errors.

--- a/liblcdf/gifread.c
+++ b/liblcdf/gifread.c
@@ -57,7 +57,7 @@
   int is_record;
   int is_eoi;
   uint8_t (*byte_getter)(struct Gif_Reader *);
-  void (*block_getter)(uint8_t *, uint32_t, struct Gif_Reader *);
+  int (*block_getter)(uint8_t *, uint32_t, struct Gif_Reader *);
   uint32_t (*offseter)(struct Gif_Reader *);
   int (*eofer)(struct Gif_Reader *);
   
@@ -86,10 +86,10 @@
   return i == EOF ? 0 : (uint8_t)i;
 }
 
-static void
+int
 file_block_getter(uint8_t *p, uint32_t s, Gif_Reader *grr)
 {
-  fread(p, 1, s, grr->f);
+  return fread(p, 1, s, grr->f) == s;
 }
 
 static uint32_t
@@ -117,12 +117,16 @@
   return grr->w ? (grr->w--, *grr->v++) : 0;
 }
 
-static void
+static int
 record_block_getter(uint8_t *p, uint32_t s, Gif_Reader *grr)
 {
-  if (s > grr->w) s = grr->w;
+  int res;
+  res = (s <= grr->w);
+  if (!res)
+    s = grr->w;
   memcpy(p, grr->v, s);
   grr->w -= s, grr->v += s;
+  return res;
 }
 
 static uint32_t
@@ -215,7 +219,8 @@
     block_len = gifgetbyte(grr);
     GIF_DEBUG(("\nimage_block(%d)", block_len));
     if (block_len == 0) return 0;
-    gifgetblock(buffer + bit_length / 8, block_len, grr);
+    if (!gifgetblock(buffer + bit_length / 8, block_len, grr))
+      return 0;
     bit_length += block_len * 8;
   }
   
@@ -362,7 +367,8 @@
   i = gifgetbyte(grr);
   GIF_DEBUG(("\nafter_image(%d)\n", i));
   while (i > 0) {
-    gifgetblock(buffer, i, grr);
+    if (!gifgetblock(buffer, i, grr))
+      break;
     i = gifgetbyte(grr);
     GIF_DEBUG(("\nafter_image(%d)\n", i));
   }
@@ -477,7 +483,8 @@
 	if (!comp) return 0;
       }
       comp[comp_len] = i;
-      gifgetblock(comp + comp_len + 1, i, grr);
+      if (!gifgetblock(comp + comp_len + 1, i, grr))
+	break;
       comp_len += i + 1;
       i = gifgetbyte(grr);
     }
@@ -584,7 +591,8 @@
     uint8_t buffer[GIF_MAX_BLOCK];
     int i = gifgetbyte(grr);
     while (i > 0) {
-      gifgetblock(buffer, i, grr);
+      if (!gifgetblock(buffer, i, grr))
+	break;
       i = gifgetbyte(grr);
     }
   }
@@ -614,13 +622,15 @@
   
   if (len > 0) {
     gif_read_error(gfc, "odd graphic extension format");
-    gifgetblock(crap, len, grr);
+    if (!gifgetblock(crap, len, grr))
+      return;
   }
   
   len = gifgetbyte(grr);
   while (len > 0) {
     gif_read_error(gfc, "odd graphic extension format");
-    gifgetblock(crap, len, grr);
+    if (!gifgetblock(crap, len, grr))
+      break;
     len = gifgetbyte(grr);
   }
 }
@@ -638,7 +648,8 @@
   while (len > 0) {
     Gif_ReArray(data, char, total_len + len + 1);
     if (!data) return 0;
-    gifgetblock((uint8_t *)data, len, grr);
+    if (!gifgetblock((uint8_t *)data, len, grr))
+      break;
     
     total_len += len;
     data[total_len] = 0;
@@ -664,7 +675,8 @@
     if (data) Gif_ReArray(data, uint8_t, data_len + block_len + 1);
     else data = Gif_NewArray(uint8_t, block_len + 1);
     if (!data) goto done;
-    gifgetblock(data + data_len, block_len, grr);
+    if (!gifgetblock(data + data_len, block_len, grr))
+      break;
     data_len += block_len;
     block_len = gifgetbyte(grr);
   }
@@ -682,7 +694,8 @@
   if (!gfex) Gif_DeleteArray(data);
   while (block_len > 0) {
     uint8_t buffer[GIF_MAX_BLOCK];
-    gifgetblock(buffer, block_len, grr);
+    if (!gifgetblock(buffer, block_len, grr))
+      break;
     block_len = gifgetbyte(grr);
   }
   return gfex != 0;
@@ -695,7 +708,10 @@
   Gif_Stream *gfs = gfc->stream;
   uint8_t buffer[GIF_MAX_BLOCK + 1];
   uint8_t len = gifgetbyte(grr);
-  gifgetblock(buffer, len, grr);
+  if (!gifgetblock(buffer, len, grr)) {
+    gif_read_error(gfc, "bad application extension");
+    return 0;
+  }
   
   /* Read the Netscape loop extension. */
   if (len == 11 && memcmp(buffer, "NETSCAPE2.0", 11) == 0) {
@@ -710,7 +726,8 @@
       gif_read_error(gfc, "bad loop extension");
     
     while (len > 0) {
-      gifgetblock(buffer, len, grr);
+      if (!gifgetblock(buffer, len, grr))
+	break;
       len = gifgetbyte(grr);
     }
     return 1;