mirror of
https://git.FreeBSD.org/ports.git
synced 2024-12-23 04:23:08 +00:00
Fix vulnerabilities in imported xpdf code.
http://www.kde.org/info/security/advisory-20041021-1.txt
This commit is contained in:
parent
e7d0ae0a0a
commit
22c870788b
Notes:
svn2git
2021-03-31 03:12:20 +00:00
svn path=/head/; revision=120078
@ -8,6 +8,7 @@
|
||||
|
||||
PORTNAME= koffice
|
||||
PORTVERSION= 1.3.2
|
||||
PORTREVISION= 1
|
||||
PORTEPOCH= 1
|
||||
CATEGORIES= editors kde
|
||||
MASTER_SITES= ${MASTER_SITE_KDE}
|
||||
@ -37,6 +38,7 @@ USE_GMAKE= yes
|
||||
USE_ICONV= yes
|
||||
USE_PYTHON= yes
|
||||
GNU_CONFIGURE= yes
|
||||
_NO_KDE_CLOSURE= yes
|
||||
|
||||
INSTALLS_SHLIB= yes
|
||||
LDCONFIG_DIRS+= %%PREFIX%%/lib %%PREFIX%%/lib/kde3
|
||||
|
@ -0,0 +1,27 @@
|
||||
--- filters/kword/pdf/xpdf/xpdf/Catalog.cc.orig 2004-10-18 16:26:39.388666476 +0200
|
||||
+++ filters/kword/pdf/xpdf/xpdf/Catalog.cc 2004-10-18 16:27:28.004749073 +0200
|
||||
@@ -62,6 +62,12 @@
|
||||
}
|
||||
pagesSize = numPages0 = obj.getInt();
|
||||
obj.free();
|
||||
+ if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
|
||||
+ pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
|
||||
+ error(-1, "Invalid 'pagesSize'");
|
||||
+ ok = gFalse;
|
||||
+ return;
|
||||
+ }
|
||||
pages = (Page **)gmalloc(pagesSize * sizeof(Page *));
|
||||
pageRefs = (Ref *)gmalloc(pagesSize * sizeof(Ref));
|
||||
for (i = 0; i < pagesSize; ++i) {
|
||||
@@ -186,6 +192,11 @@
|
||||
}
|
||||
if (start >= pagesSize) {
|
||||
pagesSize += 32;
|
||||
+ if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
|
||||
+ pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
|
||||
+ error(-1, "Invalid 'pagesSize' parameter.");
|
||||
+ goto err3;
|
||||
+ }
|
||||
pages = (Page **)grealloc(pages, pagesSize * sizeof(Page *));
|
||||
pageRefs = (Ref *)grealloc(pageRefs, pagesSize * sizeof(Ref));
|
||||
for (j = pagesSize - 32; j < pagesSize; ++j) {
|
@ -0,0 +1,49 @@
|
||||
--- filters/kword/pdf/xpdf/xpdf/XRef.cc.orig 2004-09-17 23:54:38.000000000 -0700
|
||||
+++ filters/kword/pdf/xpdf/xpdf/XRef.cc 2004-09-25 17:59:36.000000000 -0700
|
||||
@@ -76,6 +76,12 @@
|
||||
|
||||
// trailer is ok - read the xref table
|
||||
} else {
|
||||
+ if (size*sizeof(XRefEntry)/sizeof(XRefEntry) != size) {
|
||||
+ error(-1, "Invalid 'size' inside xref table.");
|
||||
+ ok = gFalse;
|
||||
+ errCode = errDamaged;
|
||||
+ return;
|
||||
+ }
|
||||
entries = (XRefEntry *)gmalloc(size * sizeof(XRefEntry));
|
||||
for (i = 0; i < size; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
@@ -267,6 +273,10 @@
|
||||
// table size
|
||||
if (first + n > size) {
|
||||
newSize = size + 256;
|
||||
+ if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
|
||||
+ error(-1, "Invalid 'newSize'");
|
||||
+ goto err2;
|
||||
+ }
|
||||
entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry));
|
||||
for (i = size; i < newSize; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
@@ -410,6 +420,10 @@
|
||||
if (!strncmp(p, "obj", 3)) {
|
||||
if (num >= size) {
|
||||
newSize = (num + 1 + 255) & ~255;
|
||||
+ if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
|
||||
+ error(-1, "Invalid 'obj' parameters.");
|
||||
+ return gFalse;
|
||||
+ }
|
||||
entries = (XRefEntry *)
|
||||
grealloc(entries, newSize * sizeof(XRefEntry));
|
||||
for (i = size; i < newSize; ++i) {
|
||||
@@ -431,6 +445,11 @@
|
||||
} else if (!strncmp(p, "endstream", 9)) {
|
||||
if (streamEndsLen == streamEndsSize) {
|
||||
streamEndsSize += 64;
|
||||
+ if (streamEndsSize*sizeof(int)/sizeof(int) != streamEndsSize) {
|
||||
+ error(-1, "Invalid 'endstream' parameter.");
|
||||
+ return gFalse;
|
||||
+ }
|
||||
+
|
||||
streamEnds = (Guint *)grealloc(streamEnds,
|
||||
streamEndsSize * sizeof(int));
|
||||
}
|
@ -8,6 +8,7 @@
|
||||
|
||||
PORTNAME= koffice
|
||||
PORTVERSION= 1.3.2
|
||||
PORTREVISION= 1
|
||||
PORTEPOCH= 1
|
||||
CATEGORIES= editors kde
|
||||
MASTER_SITES= ${MASTER_SITE_KDE}
|
||||
@ -37,6 +38,7 @@ USE_GMAKE= yes
|
||||
USE_ICONV= yes
|
||||
USE_PYTHON= yes
|
||||
GNU_CONFIGURE= yes
|
||||
_NO_KDE_CLOSURE= yes
|
||||
|
||||
INSTALLS_SHLIB= yes
|
||||
LDCONFIG_DIRS+= %%PREFIX%%/lib %%PREFIX%%/lib/kde3
|
||||
|
@ -0,0 +1,27 @@
|
||||
--- filters/kword/pdf/xpdf/xpdf/Catalog.cc.orig 2004-10-18 16:26:39.388666476 +0200
|
||||
+++ filters/kword/pdf/xpdf/xpdf/Catalog.cc 2004-10-18 16:27:28.004749073 +0200
|
||||
@@ -62,6 +62,12 @@
|
||||
}
|
||||
pagesSize = numPages0 = obj.getInt();
|
||||
obj.free();
|
||||
+ if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
|
||||
+ pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
|
||||
+ error(-1, "Invalid 'pagesSize'");
|
||||
+ ok = gFalse;
|
||||
+ return;
|
||||
+ }
|
||||
pages = (Page **)gmalloc(pagesSize * sizeof(Page *));
|
||||
pageRefs = (Ref *)gmalloc(pagesSize * sizeof(Ref));
|
||||
for (i = 0; i < pagesSize; ++i) {
|
||||
@@ -186,6 +192,11 @@
|
||||
}
|
||||
if (start >= pagesSize) {
|
||||
pagesSize += 32;
|
||||
+ if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
|
||||
+ pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
|
||||
+ error(-1, "Invalid 'pagesSize' parameter.");
|
||||
+ goto err3;
|
||||
+ }
|
||||
pages = (Page **)grealloc(pages, pagesSize * sizeof(Page *));
|
||||
pageRefs = (Ref *)grealloc(pageRefs, pagesSize * sizeof(Ref));
|
||||
for (j = pagesSize - 32; j < pagesSize; ++j) {
|
@ -0,0 +1,49 @@
|
||||
--- filters/kword/pdf/xpdf/xpdf/XRef.cc.orig 2004-09-17 23:54:38.000000000 -0700
|
||||
+++ filters/kword/pdf/xpdf/xpdf/XRef.cc 2004-09-25 17:59:36.000000000 -0700
|
||||
@@ -76,6 +76,12 @@
|
||||
|
||||
// trailer is ok - read the xref table
|
||||
} else {
|
||||
+ if (size*sizeof(XRefEntry)/sizeof(XRefEntry) != size) {
|
||||
+ error(-1, "Invalid 'size' inside xref table.");
|
||||
+ ok = gFalse;
|
||||
+ errCode = errDamaged;
|
||||
+ return;
|
||||
+ }
|
||||
entries = (XRefEntry *)gmalloc(size * sizeof(XRefEntry));
|
||||
for (i = 0; i < size; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
@@ -267,6 +273,10 @@
|
||||
// table size
|
||||
if (first + n > size) {
|
||||
newSize = size + 256;
|
||||
+ if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
|
||||
+ error(-1, "Invalid 'newSize'");
|
||||
+ goto err2;
|
||||
+ }
|
||||
entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry));
|
||||
for (i = size; i < newSize; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
@@ -410,6 +420,10 @@
|
||||
if (!strncmp(p, "obj", 3)) {
|
||||
if (num >= size) {
|
||||
newSize = (num + 1 + 255) & ~255;
|
||||
+ if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
|
||||
+ error(-1, "Invalid 'obj' parameters.");
|
||||
+ return gFalse;
|
||||
+ }
|
||||
entries = (XRefEntry *)
|
||||
grealloc(entries, newSize * sizeof(XRefEntry));
|
||||
for (i = size; i < newSize; ++i) {
|
||||
@@ -431,6 +445,11 @@
|
||||
} else if (!strncmp(p, "endstream", 9)) {
|
||||
if (streamEndsLen == streamEndsSize) {
|
||||
streamEndsSize += 64;
|
||||
+ if (streamEndsSize*sizeof(int)/sizeof(int) != streamEndsSize) {
|
||||
+ error(-1, "Invalid 'endstream' parameter.");
|
||||
+ return gFalse;
|
||||
+ }
|
||||
+
|
||||
streamEnds = (Guint *)grealloc(streamEnds,
|
||||
streamEndsSize * sizeof(int));
|
||||
}
|
@ -8,6 +8,7 @@
|
||||
|
||||
PORTNAME= koffice
|
||||
PORTVERSION= 1.3.2
|
||||
PORTREVISION= 1
|
||||
PORTEPOCH= 1
|
||||
CATEGORIES= editors kde
|
||||
MASTER_SITES= ${MASTER_SITE_KDE}
|
||||
@ -37,6 +38,7 @@ USE_GMAKE= yes
|
||||
USE_ICONV= yes
|
||||
USE_PYTHON= yes
|
||||
GNU_CONFIGURE= yes
|
||||
_NO_KDE_CLOSURE= yes
|
||||
|
||||
INSTALLS_SHLIB= yes
|
||||
LDCONFIG_DIRS+= %%PREFIX%%/lib %%PREFIX%%/lib/kde3
|
||||
|
@ -0,0 +1,27 @@
|
||||
--- filters/kword/pdf/xpdf/xpdf/Catalog.cc.orig 2004-10-18 16:26:39.388666476 +0200
|
||||
+++ filters/kword/pdf/xpdf/xpdf/Catalog.cc 2004-10-18 16:27:28.004749073 +0200
|
||||
@@ -62,6 +62,12 @@
|
||||
}
|
||||
pagesSize = numPages0 = obj.getInt();
|
||||
obj.free();
|
||||
+ if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
|
||||
+ pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
|
||||
+ error(-1, "Invalid 'pagesSize'");
|
||||
+ ok = gFalse;
|
||||
+ return;
|
||||
+ }
|
||||
pages = (Page **)gmalloc(pagesSize * sizeof(Page *));
|
||||
pageRefs = (Ref *)gmalloc(pagesSize * sizeof(Ref));
|
||||
for (i = 0; i < pagesSize; ++i) {
|
||||
@@ -186,6 +192,11 @@
|
||||
}
|
||||
if (start >= pagesSize) {
|
||||
pagesSize += 32;
|
||||
+ if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
|
||||
+ pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
|
||||
+ error(-1, "Invalid 'pagesSize' parameter.");
|
||||
+ goto err3;
|
||||
+ }
|
||||
pages = (Page **)grealloc(pages, pagesSize * sizeof(Page *));
|
||||
pageRefs = (Ref *)grealloc(pageRefs, pagesSize * sizeof(Ref));
|
||||
for (j = pagesSize - 32; j < pagesSize; ++j) {
|
@ -0,0 +1,49 @@
|
||||
--- filters/kword/pdf/xpdf/xpdf/XRef.cc.orig 2004-09-17 23:54:38.000000000 -0700
|
||||
+++ filters/kword/pdf/xpdf/xpdf/XRef.cc 2004-09-25 17:59:36.000000000 -0700
|
||||
@@ -76,6 +76,12 @@
|
||||
|
||||
// trailer is ok - read the xref table
|
||||
} else {
|
||||
+ if (size*sizeof(XRefEntry)/sizeof(XRefEntry) != size) {
|
||||
+ error(-1, "Invalid 'size' inside xref table.");
|
||||
+ ok = gFalse;
|
||||
+ errCode = errDamaged;
|
||||
+ return;
|
||||
+ }
|
||||
entries = (XRefEntry *)gmalloc(size * sizeof(XRefEntry));
|
||||
for (i = 0; i < size; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
@@ -267,6 +273,10 @@
|
||||
// table size
|
||||
if (first + n > size) {
|
||||
newSize = size + 256;
|
||||
+ if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
|
||||
+ error(-1, "Invalid 'newSize'");
|
||||
+ goto err2;
|
||||
+ }
|
||||
entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry));
|
||||
for (i = size; i < newSize; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
@@ -410,6 +420,10 @@
|
||||
if (!strncmp(p, "obj", 3)) {
|
||||
if (num >= size) {
|
||||
newSize = (num + 1 + 255) & ~255;
|
||||
+ if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
|
||||
+ error(-1, "Invalid 'obj' parameters.");
|
||||
+ return gFalse;
|
||||
+ }
|
||||
entries = (XRefEntry *)
|
||||
grealloc(entries, newSize * sizeof(XRefEntry));
|
||||
for (i = size; i < newSize; ++i) {
|
||||
@@ -431,6 +445,11 @@
|
||||
} else if (!strncmp(p, "endstream", 9)) {
|
||||
if (streamEndsLen == streamEndsSize) {
|
||||
streamEndsSize += 64;
|
||||
+ if (streamEndsSize*sizeof(int)/sizeof(int) != streamEndsSize) {
|
||||
+ error(-1, "Invalid 'endstream' parameter.");
|
||||
+ return gFalse;
|
||||
+ }
|
||||
+
|
||||
streamEnds = (Guint *)grealloc(streamEnds,
|
||||
streamEndsSize * sizeof(int));
|
||||
}
|
@ -8,6 +8,7 @@
|
||||
|
||||
PORTNAME= kdegraphics
|
||||
PORTVERSION= ${KDE_VERSION}
|
||||
PORTREVISION= 1
|
||||
CATEGORIES= graphics kde
|
||||
MASTER_SITES= ${MASTER_SITE_KDE}
|
||||
MASTER_SITE_SUBDIR= stable/${PORTVERSION:S/.0//}/src
|
||||
|
35
graphics/kdegraphics3/files/patch-kpdf_xpdf_Catalog.cc
Normal file
35
graphics/kdegraphics3/files/patch-kpdf_xpdf_Catalog.cc
Normal file
@ -0,0 +1,35 @@
|
||||
--- kpdf/xpdf/Catalog.cc 20 Aug 2003 21:25:12 -0000 1.3
|
||||
+++ kpdf/xpdf/Catalog.cc 18 Oct 2004 20:12:09 -0000
|
||||
@@ -61,10 +61,16 @@ Catalog::Catalog(XRef *xrefA) {
|
||||
obj.getTypeName());
|
||||
goto err3;
|
||||
}
|
||||
pagesSize = numPages0 = obj.getInt();
|
||||
obj.free();
|
||||
+ if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
|
||||
+ pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
|
||||
+ error(-1, "Invalid 'pagesSize'");
|
||||
+ ok = gFalse;
|
||||
+ return;
|
||||
+ }
|
||||
pages = (Page **)gmalloc(pagesSize * sizeof(Page *));
|
||||
pageRefs = (Ref *)gmalloc(pagesSize * sizeof(Ref));
|
||||
for (i = 0; i < pagesSize; ++i) {
|
||||
pages[i] = NULL;
|
||||
pageRefs[i].num = -1;
|
||||
@@ -188,10 +194,15 @@ int Catalog::readPageTree(Dict *pagesDic
|
||||
++start;
|
||||
goto err3;
|
||||
}
|
||||
if (start >= pagesSize) {
|
||||
pagesSize += 32;
|
||||
+ if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
|
||||
+ pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
|
||||
+ error(-1, "Invalid 'pagesSize' parameter.");
|
||||
+ goto err3;
|
||||
+ }
|
||||
pages = (Page **)grealloc(pages, pagesSize * sizeof(Page *));
|
||||
pageRefs = (Ref *)grealloc(pageRefs, pagesSize * sizeof(Ref));
|
||||
for (j = pagesSize - 32; j < pagesSize; ++j) {
|
||||
pages[j] = NULL;
|
||||
pageRefs[j].num = -1;
|
65
graphics/kdegraphics3/files/patch-kpdf_xpdf_XRef.cc
Normal file
65
graphics/kdegraphics3/files/patch-kpdf_xpdf_XRef.cc
Normal file
@ -0,0 +1,65 @@
|
||||
--- kpdf/xpdf/XRef.cc 20 Aug 2003 21:25:12 -0000 1.3
|
||||
+++ kpdf/xpdf/XRef.cc 18 Oct 2004 20:12:09 -0000
|
||||
@@ -74,10 +74,16 @@ XRef::XRef(BaseStream *strA, GString *ow
|
||||
return;
|
||||
}
|
||||
|
||||
// trailer is ok - read the xref table
|
||||
} else {
|
||||
+ if (size*sizeof(XRefEntry)/sizeof(XRefEntry) != size) {
|
||||
+ error(-1, "Invalid 'size' inside xref table.");
|
||||
+ ok = gFalse;
|
||||
+ errCode = errDamaged;
|
||||
+ return;
|
||||
+ }
|
||||
entries = (XRefEntry *)gmalloc(size * sizeof(XRefEntry));
|
||||
for (i = 0; i < size; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
entries[i].used = gFalse;
|
||||
}
|
||||
@@ -265,10 +271,14 @@ GBool XRef::readXRef(Guint *pos) {
|
||||
}
|
||||
// check for buggy PDF files with an incorrect (too small) xref
|
||||
// table size
|
||||
if (first + n > size) {
|
||||
newSize = size + 256;
|
||||
+ if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
|
||||
+ error(-1, "Invalid 'newSize'");
|
||||
+ goto err2;
|
||||
+ }
|
||||
entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry));
|
||||
for (i = size; i < newSize; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
entries[i].used = gFalse;
|
||||
}
|
||||
@@ -413,10 +423,14 @@ GBool XRef::constructXRef() {
|
||||
++p;
|
||||
} while (*p && isspace(*p));
|
||||
if (!strncmp(p, "obj", 3)) {
|
||||
if (num >= size) {
|
||||
newSize = (num + 1 + 255) & ~255;
|
||||
+ if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
|
||||
+ error(-1, "Invalid 'obj' parameters.");
|
||||
+ return gFalse;
|
||||
+ }
|
||||
entries = (XRefEntry *)
|
||||
grealloc(entries, newSize * sizeof(XRefEntry));
|
||||
for (i = size; i < newSize; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
entries[i].used = gFalse;
|
||||
@@ -434,10 +448,15 @@ GBool XRef::constructXRef() {
|
||||
}
|
||||
|
||||
} else if (!strncmp(p, "endstream", 9)) {
|
||||
if (streamEndsLen == streamEndsSize) {
|
||||
streamEndsSize += 64;
|
||||
+ if (streamEndsSize*sizeof(int)/sizeof(int) != streamEndsSize) {
|
||||
+ error(-1, "Invalid 'endstream' parameter.");
|
||||
+ return gFalse;
|
||||
+ }
|
||||
+
|
||||
streamEnds = (Guint *)grealloc(streamEnds,
|
||||
streamEndsSize * sizeof(int));
|
||||
}
|
||||
streamEnds[streamEndsLen++] = pos;
|
||||
}
|
@ -8,6 +8,7 @@
|
||||
|
||||
PORTNAME= kdegraphics
|
||||
PORTVERSION= ${KDE_VERSION}
|
||||
PORTREVISION= 1
|
||||
CATEGORIES= graphics kde
|
||||
MASTER_SITES= ${MASTER_SITE_KDE}
|
||||
MASTER_SITE_SUBDIR= stable/${PORTVERSION:S/.0//}/src
|
||||
|
35
graphics/kdegraphics4/files/patch-kpdf_xpdf_Catalog.cc
Normal file
35
graphics/kdegraphics4/files/patch-kpdf_xpdf_Catalog.cc
Normal file
@ -0,0 +1,35 @@
|
||||
--- kpdf/xpdf/Catalog.cc 20 Aug 2003 21:25:12 -0000 1.3
|
||||
+++ kpdf/xpdf/Catalog.cc 18 Oct 2004 20:12:09 -0000
|
||||
@@ -61,10 +61,16 @@ Catalog::Catalog(XRef *xrefA) {
|
||||
obj.getTypeName());
|
||||
goto err3;
|
||||
}
|
||||
pagesSize = numPages0 = obj.getInt();
|
||||
obj.free();
|
||||
+ if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
|
||||
+ pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
|
||||
+ error(-1, "Invalid 'pagesSize'");
|
||||
+ ok = gFalse;
|
||||
+ return;
|
||||
+ }
|
||||
pages = (Page **)gmalloc(pagesSize * sizeof(Page *));
|
||||
pageRefs = (Ref *)gmalloc(pagesSize * sizeof(Ref));
|
||||
for (i = 0; i < pagesSize; ++i) {
|
||||
pages[i] = NULL;
|
||||
pageRefs[i].num = -1;
|
||||
@@ -188,10 +194,15 @@ int Catalog::readPageTree(Dict *pagesDic
|
||||
++start;
|
||||
goto err3;
|
||||
}
|
||||
if (start >= pagesSize) {
|
||||
pagesSize += 32;
|
||||
+ if (pagesSize*sizeof(Page *)/sizeof(Page *) != pagesSize ||
|
||||
+ pagesSize*sizeof(Ref)/sizeof(Ref) != pagesSize) {
|
||||
+ error(-1, "Invalid 'pagesSize' parameter.");
|
||||
+ goto err3;
|
||||
+ }
|
||||
pages = (Page **)grealloc(pages, pagesSize * sizeof(Page *));
|
||||
pageRefs = (Ref *)grealloc(pageRefs, pagesSize * sizeof(Ref));
|
||||
for (j = pagesSize - 32; j < pagesSize; ++j) {
|
||||
pages[j] = NULL;
|
||||
pageRefs[j].num = -1;
|
65
graphics/kdegraphics4/files/patch-kpdf_xpdf_XRef.cc
Normal file
65
graphics/kdegraphics4/files/patch-kpdf_xpdf_XRef.cc
Normal file
@ -0,0 +1,65 @@
|
||||
--- kpdf/xpdf/XRef.cc 20 Aug 2003 21:25:12 -0000 1.3
|
||||
+++ kpdf/xpdf/XRef.cc 18 Oct 2004 20:12:09 -0000
|
||||
@@ -74,10 +74,16 @@ XRef::XRef(BaseStream *strA, GString *ow
|
||||
return;
|
||||
}
|
||||
|
||||
// trailer is ok - read the xref table
|
||||
} else {
|
||||
+ if (size*sizeof(XRefEntry)/sizeof(XRefEntry) != size) {
|
||||
+ error(-1, "Invalid 'size' inside xref table.");
|
||||
+ ok = gFalse;
|
||||
+ errCode = errDamaged;
|
||||
+ return;
|
||||
+ }
|
||||
entries = (XRefEntry *)gmalloc(size * sizeof(XRefEntry));
|
||||
for (i = 0; i < size; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
entries[i].used = gFalse;
|
||||
}
|
||||
@@ -265,10 +271,14 @@ GBool XRef::readXRef(Guint *pos) {
|
||||
}
|
||||
// check for buggy PDF files with an incorrect (too small) xref
|
||||
// table size
|
||||
if (first + n > size) {
|
||||
newSize = size + 256;
|
||||
+ if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
|
||||
+ error(-1, "Invalid 'newSize'");
|
||||
+ goto err2;
|
||||
+ }
|
||||
entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry));
|
||||
for (i = size; i < newSize; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
entries[i].used = gFalse;
|
||||
}
|
||||
@@ -413,10 +423,14 @@ GBool XRef::constructXRef() {
|
||||
++p;
|
||||
} while (*p && isspace(*p));
|
||||
if (!strncmp(p, "obj", 3)) {
|
||||
if (num >= size) {
|
||||
newSize = (num + 1 + 255) & ~255;
|
||||
+ if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
|
||||
+ error(-1, "Invalid 'obj' parameters.");
|
||||
+ return gFalse;
|
||||
+ }
|
||||
entries = (XRefEntry *)
|
||||
grealloc(entries, newSize * sizeof(XRefEntry));
|
||||
for (i = size; i < newSize; ++i) {
|
||||
entries[i].offset = 0xffffffff;
|
||||
entries[i].used = gFalse;
|
||||
@@ -434,10 +448,15 @@ GBool XRef::constructXRef() {
|
||||
}
|
||||
|
||||
} else if (!strncmp(p, "endstream", 9)) {
|
||||
if (streamEndsLen == streamEndsSize) {
|
||||
streamEndsSize += 64;
|
||||
+ if (streamEndsSize*sizeof(int)/sizeof(int) != streamEndsSize) {
|
||||
+ error(-1, "Invalid 'endstream' parameter.");
|
||||
+ return gFalse;
|
||||
+ }
|
||||
+
|
||||
streamEnds = (Guint *)grealloc(streamEnds,
|
||||
streamEndsSize * sizeof(int));
|
||||
}
|
||||
streamEnds[streamEndsLen++] = pos;
|
||||
}
|
Loading…
Reference in New Issue
Block a user