Backport fixes for CVE-2016-7163
This commit is contained in:
parent
303d6c80ba
commit
1010d3038d
30
c16bc057ba3f125051c9966cf1f5b68a05681de4.patch
Normal file
30
c16bc057ba3f125051c9966cf1f5b68a05681de4.patch
Normal file
@ -0,0 +1,30 @@
|
||||
From c16bc057ba3f125051c9966cf1f5b68a05681de4 Mon Sep 17 00:00:00 2001
|
||||
From: trylab <trylab@users.noreply.github.com>
|
||||
Date: Tue, 6 Sep 2016 13:55:49 +0800
|
||||
Subject: [PATCH] Fix an integer overflow issue (#809)
|
||||
|
||||
Prevent an integer overflow issue in function opj_pi_create_decode of
|
||||
pi.c.
|
||||
---
|
||||
src/lib/openjp2/pi.c | 8 +++++++-
|
||||
1 file changed, 7 insertions(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/openjp2/pi.c b/src/lib/openjp2/pi.c
|
||||
index cffad66..36e2ff0 100644
|
||||
--- a/src/lib/openjp2/pi.c
|
||||
+++ b/src/lib/openjp2/pi.c
|
||||
@@ -1237,7 +1237,13 @@ opj_pi_iterator_t *opj_pi_create_decode(opj_image_t *p_image,
|
||||
l_current_pi = l_pi;
|
||||
|
||||
/* memory allocation for include */
|
||||
- l_current_pi->include = (OPJ_INT16*) opj_calloc((l_tcp->numlayers +1) * l_step_l, sizeof(OPJ_INT16));
|
||||
+ /* prevent an integer overflow issue */
|
||||
+ l_current_pi->include = 00;
|
||||
+ if (l_step_l <= (SIZE_MAX / (l_tcp->numlayers + 1U)))
|
||||
+ {
|
||||
+ l_current_pi->include = (OPJ_INT16*) opj_calloc((l_tcp->numlayers +1) * l_step_l, sizeof(OPJ_INT16));
|
||||
+ }
|
||||
+
|
||||
if
|
||||
(!l_current_pi->include)
|
||||
{
|
||||
23
ef01f18dfc6780b776d0674ed3e7415c6ef54d24.patch
Normal file
23
ef01f18dfc6780b776d0674ed3e7415c6ef54d24.patch
Normal file
@ -0,0 +1,23 @@
|
||||
From ef01f18dfc6780b776d0674ed3e7415c6ef54d24 Mon Sep 17 00:00:00 2001
|
||||
From: Matthieu Darbois <mayeut@users.noreply.github.com>
|
||||
Date: Thu, 8 Sep 2016 07:34:46 +0200
|
||||
Subject: [PATCH] Cast to size_t before multiplication
|
||||
|
||||
Need to cast to size_t before multiplication otherwise overflow check is useless.
|
||||
---
|
||||
src/lib/openjp2/pi.c | 2 +-
|
||||
1 file changed, 1 insertion(+), 1 deletion(-)
|
||||
|
||||
diff --git a/src/lib/openjp2/pi.c b/src/lib/openjp2/pi.c
|
||||
index 36e2ff0..809b33d 100644
|
||||
--- a/src/lib/openjp2/pi.c
|
||||
+++ b/src/lib/openjp2/pi.c
|
||||
@@ -1241,7 +1241,7 @@ opj_pi_iterator_t *opj_pi_create_decode(opj_image_t *p_image,
|
||||
l_current_pi->include = 00;
|
||||
if (l_step_l <= (SIZE_MAX / (l_tcp->numlayers + 1U)))
|
||||
{
|
||||
- l_current_pi->include = (OPJ_INT16*) opj_calloc((l_tcp->numlayers +1) * l_step_l, sizeof(OPJ_INT16));
|
||||
+ l_current_pi->include = (OPJ_INT16*) opj_calloc((size_t)(l_tcp->numlayers + 1U) * l_step_l, sizeof(OPJ_INT16));
|
||||
}
|
||||
|
||||
if
|
||||
@ -5,7 +5,7 @@
|
||||
|
||||
Name: openjpeg2
|
||||
Version: 2.1.1
|
||||
Release: 1%{?dist}
|
||||
Release: 2%{?dist}
|
||||
Summary: C-Library for JPEG 2000
|
||||
|
||||
# windirent.h is MIT, the rest is BSD
|
||||
@ -19,6 +19,10 @@ Source1: data.tar.xz
|
||||
|
||||
# Remove bundled libraries
|
||||
Patch0: openjpeg2_remove-thirdparty.patch
|
||||
# Backport: Prevent an integer overflow issue in function opj_pi_create_decode of pi.c. (CVE-2016-7163)
|
||||
Patch1: c16bc057ba3f125051c9966cf1f5b68a05681de4.patch
|
||||
# Backport: Need to cast to size_t before multiplication otherwise overflow check is useless. (CVE-2016-7163)
|
||||
Patch2: ef01f18dfc6780b776d0674ed3e7415c6ef54d24.patch
|
||||
|
||||
BuildRequires: cmake
|
||||
BuildRequires: zlib-devel
|
||||
@ -195,6 +199,8 @@ OpenJPEG2 JP3D module command line tools
|
||||
%prep
|
||||
%setup -q -n openjpeg-%{version} %{?runcheck:-a 1}
|
||||
%patch0 -p1
|
||||
%patch1 -p1
|
||||
%patch2 -p1
|
||||
|
||||
# Remove all third party libraries just to be sure
|
||||
rm -rf thirdparty
|
||||
@ -324,6 +330,9 @@ make test -C %{_target_platform}
|
||||
|
||||
|
||||
%changelog
|
||||
* Fri Sep 09 2016 Sandro Mani <manisandro@gmail.com> - 2.1.1-2
|
||||
- Backport fixes for CVE-2016-7163
|
||||
|
||||
* Wed Jul 06 2016 Sandro Mani <manisandro@gmail.com> - 2.1.1-1
|
||||
- Update to 2.1.1
|
||||
- Fixes: CVE-2016-3183, CVE-2016-3181, CVE-2016-3182, CVE-2016-4796, CVE-2016-4797, CVE-2015-8871
|
||||
|
||||
Loading…
Reference in New Issue
Block a user