summaryrefslogtreecommitdiff
path: root/graphics/kdegraphics3/files/patch-kpdf_xpdf_XRef.cc
blob: 696b795b3b6d867c8dc91f51c35d75c546957983 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
--- kpdf/xpdf/XRef.cc	20 Aug 2003 21:25:12 -0000	1.3
+++ kpdf/xpdf/XRef.cc	18 Oct 2004 20:12:09 -0000
@@ -74,10 +74,16 @@ XRef::XRef(BaseStream *strA, GString *ow
       return;
     }
 
   // trailer is ok - read the xref table
   } else {
+    if (size*sizeof(XRefEntry)/sizeof(XRefEntry) != size) {
+      error(-1, "Invalid 'size' inside xref table.");
+      ok = gFalse;
+      errCode = errDamaged;
+      return;
+    }
     entries = (XRefEntry *)gmalloc(size * sizeof(XRefEntry));
     for (i = 0; i < size; ++i) {
       entries[i].offset = 0xffffffff;
       entries[i].used = gFalse;
     }
@@ -265,10 +271,14 @@ GBool XRef::readXRef(Guint *pos) {
     }
     // check for buggy PDF files with an incorrect (too small) xref
     // table size
     if (first + n > size) {
       newSize = size + 256;
+      if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
+        error(-1, "Invalid 'newSize'");
+        goto err2;
+      }
       entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry));
       for (i = size; i < newSize; ++i) {
 	entries[i].offset = 0xffffffff;
 	entries[i].used = gFalse;
       }
@@ -413,10 +423,14 @@ GBool XRef::constructXRef() {
 	      ++p;
 	    } while (*p && isspace(*p));
 	    if (!strncmp(p, "obj", 3)) {
 	      if (num >= size) {
 		newSize = (num + 1 + 255) & ~255;
+	        if (newSize*sizeof(XRefEntry)/sizeof(XRefEntry) != newSize) {
+	          error(-1, "Invalid 'obj' parameters.");
+	          return gFalse;
+	        }
 		entries = (XRefEntry *)
 		            grealloc(entries, newSize * sizeof(XRefEntry));
 		for (i = size; i < newSize; ++i) {
 		  entries[i].offset = 0xffffffff;
 		  entries[i].used = gFalse;
@@ -434,10 +448,15 @@ GBool XRef::constructXRef() {
       }
 
     } else if (!strncmp(p, "endstream", 9)) {
       if (streamEndsLen == streamEndsSize) {
 	streamEndsSize += 64;
+        if (streamEndsSize*sizeof(int)/sizeof(int) != streamEndsSize) {
+          error(-1, "Invalid 'endstream' parameter.");
+          return gFalse;
+        }
+
 	streamEnds = (Guint *)grealloc(streamEnds,
 				       streamEndsSize * sizeof(int));
       }
       streamEnds[streamEndsLen++] = pos;
     }