From 1010d3038d6768de8e1c607e565ca0621b633a88 Mon Sep 17 00:00:00 2001 From: Sandro Mani Date: Fri, 9 Sep 2016 11:53:12 +0200 Subject: [PATCH] Backport fixes for CVE-2016-7163 --- ...c057ba3f125051c9966cf1f5b68a05681de4.patch | 30 +++++++++++++++++++ ...f18dfc6780b776d0674ed3e7415c6ef54d24.patch | 23 ++++++++++++++ openjpeg2.spec | 11 ++++++- 3 files changed, 63 insertions(+), 1 deletion(-) create mode 100644 c16bc057ba3f125051c9966cf1f5b68a05681de4.patch create mode 100644 ef01f18dfc6780b776d0674ed3e7415c6ef54d24.patch diff --git a/c16bc057ba3f125051c9966cf1f5b68a05681de4.patch b/c16bc057ba3f125051c9966cf1f5b68a05681de4.patch new file mode 100644 index 0000000..137a02d --- /dev/null +++ b/c16bc057ba3f125051c9966cf1f5b68a05681de4.patch @@ -0,0 +1,30 @@ +From c16bc057ba3f125051c9966cf1f5b68a05681de4 Mon Sep 17 00:00:00 2001 +From: trylab +Date: Tue, 6 Sep 2016 13:55:49 +0800 +Subject: [PATCH] Fix an integer overflow issue (#809) + +Prevent an integer overflow issue in function opj_pi_create_decode of +pi.c. +--- + src/lib/openjp2/pi.c | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/src/lib/openjp2/pi.c b/src/lib/openjp2/pi.c +index cffad66..36e2ff0 100644 +--- a/src/lib/openjp2/pi.c ++++ b/src/lib/openjp2/pi.c +@@ -1237,7 +1237,13 @@ opj_pi_iterator_t *opj_pi_create_decode(opj_image_t *p_image, + l_current_pi = l_pi; + + /* memory allocation for include */ +- l_current_pi->include = (OPJ_INT16*) opj_calloc((l_tcp->numlayers +1) * l_step_l, sizeof(OPJ_INT16)); ++ /* prevent an integer overflow issue */ ++ l_current_pi->include = 00; ++ if (l_step_l <= (SIZE_MAX / (l_tcp->numlayers + 1U))) ++ { ++ l_current_pi->include = (OPJ_INT16*) opj_calloc((l_tcp->numlayers +1) * l_step_l, sizeof(OPJ_INT16)); ++ } ++ + if + (!l_current_pi->include) + { diff --git a/ef01f18dfc6780b776d0674ed3e7415c6ef54d24.patch b/ef01f18dfc6780b776d0674ed3e7415c6ef54d24.patch new file mode 100644 index 0000000..99578ae --- /dev/null +++ b/ef01f18dfc6780b776d0674ed3e7415c6ef54d24.patch @@ -0,0 +1,23 @@ +From ef01f18dfc6780b776d0674ed3e7415c6ef54d24 Mon Sep 17 00:00:00 2001 +From: Matthieu Darbois +Date: Thu, 8 Sep 2016 07:34:46 +0200 +Subject: [PATCH] Cast to size_t before multiplication + +Need to cast to size_t before multiplication otherwise overflow check is useless. +--- + src/lib/openjp2/pi.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/lib/openjp2/pi.c b/src/lib/openjp2/pi.c +index 36e2ff0..809b33d 100644 +--- a/src/lib/openjp2/pi.c ++++ b/src/lib/openjp2/pi.c +@@ -1241,7 +1241,7 @@ opj_pi_iterator_t *opj_pi_create_decode(opj_image_t *p_image, + l_current_pi->include = 00; + if (l_step_l <= (SIZE_MAX / (l_tcp->numlayers + 1U))) + { +- l_current_pi->include = (OPJ_INT16*) opj_calloc((l_tcp->numlayers +1) * l_step_l, sizeof(OPJ_INT16)); ++ l_current_pi->include = (OPJ_INT16*) opj_calloc((size_t)(l_tcp->numlayers + 1U) * l_step_l, sizeof(OPJ_INT16)); + } + + if diff --git a/openjpeg2.spec b/openjpeg2.spec index 8d14358..99eb94a 100644 --- a/openjpeg2.spec +++ b/openjpeg2.spec @@ -5,7 +5,7 @@ Name: openjpeg2 Version: 2.1.1 -Release: 1%{?dist} +Release: 2%{?dist} Summary: C-Library for JPEG 2000 # windirent.h is MIT, the rest is BSD @@ -19,6 +19,10 @@ Source1: data.tar.xz # Remove bundled libraries Patch0: openjpeg2_remove-thirdparty.patch +# Backport: Prevent an integer overflow issue in function opj_pi_create_decode of pi.c. (CVE-2016-7163) +Patch1: c16bc057ba3f125051c9966cf1f5b68a05681de4.patch +# Backport: Need to cast to size_t before multiplication otherwise overflow check is useless. (CVE-2016-7163) +Patch2: ef01f18dfc6780b776d0674ed3e7415c6ef54d24.patch BuildRequires: cmake BuildRequires: zlib-devel @@ -195,6 +199,8 @@ OpenJPEG2 JP3D module command line tools %prep %setup -q -n openjpeg-%{version} %{?runcheck:-a 1} %patch0 -p1 +%patch1 -p1 +%patch2 -p1 # Remove all third party libraries just to be sure rm -rf thirdparty @@ -324,6 +330,9 @@ make test -C %{_target_platform} %changelog +* Fri Sep 09 2016 Sandro Mani - 2.1.1-2 +- Backport fixes for CVE-2016-7163 + * Wed Jul 06 2016 Sandro Mani - 2.1.1-1 - Update to 2.1.1 - Fixes: CVE-2016-3183, CVE-2016-3181, CVE-2016-3182, CVE-2016-4796, CVE-2016-4797, CVE-2015-8871