|
| 1 | +From 4ced19ffd2d1d1ce63baa9be551f789a4927c37e Mon Sep 17 00:00:00 2001 |
| 2 | +From: Michael Adams < [email protected]> |
| 3 | +Date: Sat, 2 Aug 2025 18:00:39 -0700 |
| 4 | +Subject: [PATCH] Fixes #401. |
| 5 | + |
| 6 | +JPEG-2000 (JPC) Encoder: |
| 7 | +- Added some missing range checking on several coding parameters |
| 8 | + (e.g., precint width/height and codeblock width/height). |
| 9 | + |
| 10 | +Signed-off-by: Azure Linux Security Servicing Account < [email protected]> |
| 11 | +Upstream-reference: https://github.com/jasper-software/jasper/commit/79185d32d7a444abae441935b20ae4676b3513d4.patch |
| 12 | +--- |
| 13 | + src/libjasper/jpc/jpc_enc.c | 30 ++++++++++++++++++++++++------ |
| 14 | + src/libjasper/jpc/jpc_t2dec.c | 3 ++- |
| 15 | + 2 files changed, 26 insertions(+), 7 deletions(-) |
| 16 | + |
| 17 | +diff --git a/src/libjasper/jpc/jpc_enc.c b/src/libjasper/jpc/jpc_enc.c |
| 18 | +index 93013f9..c957e3f 100644 |
| 19 | +--- a/src/libjasper/jpc/jpc_enc.c |
| 20 | ++++ b/src/libjasper/jpc/jpc_enc.c |
| 21 | +@@ -474,18 +474,36 @@ static jpc_enc_cp_t *cp_create(const char *optstr, jas_image_t *image) |
| 22 | + cp->tileheight = atoi(jas_tvparser_getval(tvp)); |
| 23 | + break; |
| 24 | + case OPT_PRCWIDTH: |
| 25 | +- prcwidthexpn = jpc_floorlog2(atoi(jas_tvparser_getval(tvp))); |
| 26 | ++ i = atoi(jas_tvparser_getval(tvp)); |
| 27 | ++ if (i <= 0) { |
| 28 | ++ jas_eprintf("invalid precinct width (%d)\n", i); |
| 29 | ++ goto error; |
| 30 | ++ } |
| 31 | ++ prcwidthexpn = jpc_floorlog2(i); |
| 32 | + break; |
| 33 | + case OPT_PRCHEIGHT: |
| 34 | +- prcheightexpn = jpc_floorlog2(atoi(jas_tvparser_getval(tvp))); |
| 35 | ++ i = atoi(jas_tvparser_getval(tvp)); |
| 36 | ++ if (i <= 0) { |
| 37 | ++ jas_eprintf("invalid precinct height (%d)\n", i); |
| 38 | ++ goto error; |
| 39 | ++ } |
| 40 | ++ prcheightexpn = jpc_floorlog2(i); |
| 41 | + break; |
| 42 | + case OPT_CBLKWIDTH: |
| 43 | +- tccp->cblkwidthexpn = |
| 44 | +- jpc_floorlog2(atoi(jas_tvparser_getval(tvp))); |
| 45 | ++ i = atoi(jas_tvparser_getval(tvp)); |
| 46 | ++ if (i <= 0) { |
| 47 | ++ jas_eprintf("invalid code block width (%d)\n", i); |
| 48 | ++ goto error; |
| 49 | ++ } |
| 50 | ++ tccp->cblkwidthexpn = jpc_floorlog2(i); |
| 51 | + break; |
| 52 | + case OPT_CBLKHEIGHT: |
| 53 | +- tccp->cblkheightexpn = |
| 54 | +- jpc_floorlog2(atoi(jas_tvparser_getval(tvp))); |
| 55 | ++ i = atoi(jas_tvparser_getval(tvp)); |
| 56 | ++ if (i <= 0) { |
| 57 | ++ jas_eprintf("invalid code block height (%d)\n", i); |
| 58 | ++ goto error; |
| 59 | ++ } |
| 60 | ++ tccp->cblkheightexpn = jpc_floorlog2(i); |
| 61 | + break; |
| 62 | + case OPT_MODE: |
| 63 | + if ((tagid = jas_taginfo_nonull(jas_taginfos_lookup(modetab, |
| 64 | +diff --git a/src/libjasper/jpc/jpc_t2dec.c b/src/libjasper/jpc/jpc_t2dec.c |
| 65 | +index e52b549..6e1f1f7 100644 |
| 66 | +--- a/src/libjasper/jpc/jpc_t2dec.c |
| 67 | ++++ b/src/libjasper/jpc/jpc_t2dec.c |
| 68 | +@@ -337,7 +337,8 @@ static int jpc_dec_decodepkt(jpc_dec_t *dec, jas_stream_t *pkthdrstream, jas_str |
| 69 | + const unsigned n = JAS_MIN((unsigned)numnewpasses, maxpasses); |
| 70 | + mycounter += n; |
| 71 | + numnewpasses -= n; |
| 72 | +- if ((len = jpc_bitstream_getbits(inb, cblk->numlenbits + jpc_floorlog2(n))) < 0) { |
| 73 | ++ if ((len = jpc_bitstream_getbits(inb, |
| 74 | ++ cblk->numlenbits + jpc_floorlog2(n))) < 0) { |
| 75 | + jpc_bitstream_close(inb); |
| 76 | + return -1; |
| 77 | + } |
| 78 | +-- |
| 79 | +2.45.4 |
| 80 | + |
0 commit comments