Blame SOURCES/exiv2-CVE-2018-11531.patch
|
|
240d3a |
diff --git a/src/preview.cpp b/src/preview.cpp
|
|
|
240d3a |
index c34c8bd..69f8e01 100644
|
|
|
240d3a |
--- a/src/preview.cpp
|
|
|
240d3a |
+++ b/src/preview.cpp
|
|
|
240d3a |
@@ -36,6 +36,7 @@ EXIV2_RCSID("@(#) $Id$")
|
|
|
240d3a |
|
|
|
240d3a |
#include "preview.hpp"
|
|
|
240d3a |
#include "futils.hpp"
|
|
|
240d3a |
+#include "enforce.hpp"
|
|
|
240d3a |
|
|
|
240d3a |
#include "image.hpp"
|
|
|
240d3a |
#include "cr2image.hpp"
|
|
|
240d3a |
@@ -807,13 +808,14 @@ namespace {
|
|
|
240d3a |
else {
|
|
|
240d3a |
// FIXME: the buffer is probably copied twice, it should be optimized
|
|
|
240d3a |
DataBuf buf(size_);
|
|
|
240d3a |
- Exiv2::byte* pos = buf.pData_;
|
|
|
240d3a |
+ uint32_t idxBuf = 0;
|
|
|
240d3a |
for (int i = 0; i < sizes.count(); i++) {
|
|
|
240d3a |
uint32_t offset = dataValue.toLong(i);
|
|
|
240d3a |
uint32_t size = sizes.toLong(i);
|
|
|
240d3a |
- if (offset + size <= static_cast<uint32_t>(io.size()))
|
|
|
240d3a |
- memcpy(pos, base + offset, size);
|
|
|
240d3a |
- pos += size;
|
|
|
240d3a |
+ enforce(idxBuf + size < size_, kerCorruptedMetadata);
|
|
|
240d3a |
+ if (size!=0 && offset + size <= static_cast<uint32_t>(io.size()))
|
|
|
240d3a |
+ memcpy(&buf.pData_[idxBuf], base + offset, size);
|
|
|
240d3a |
+ idxBuf += size;
|
|
|
240d3a |
}
|
|
|
240d3a |
dataValue.setDataArea(buf.pData_, buf.size_);
|
|
|
240d3a |
}
|