Repository navigation
imagetoraster: reject output dimensions that overflow cupsBytesPerLine - #264
Open
ManasBagul23 wants to merge 1 commit into
Open
ManasBagul23 wants to merge 1 commit into
ManasBagul23 wants to merge 1 commit into
Conversation
header.cupsBytesPerLine was computed as:
header.cupsBytesPerLine = (header.cupsBitsPerPixel *
header.cupsWidth + 7) / 8;
Both operands are unsigned 32-bit fields. A PPD offering an extreme
RGB16 resolution together with a small, low-PPI image can drive
cupsWidth into the tens of millions; multiplied by a wide pixel depth
(e.g. 48 bits for RGB16), the product overflows 32-bit unsigned
arithmetic and wraps to a small value before the +7/8 rounds it down
to bytes. The formatter (format_cmy/format_RGB) still writes a full
row's worth of pixels, well past the undersized buffer that was
allocated from the wrapped cupsBytesPerLine.
Compute the row size in a wider type (size_t, including the
CUPS_ORDER_BANDED multiply, which could also push a borderline value
over) and reject the page if it doesn't fit in the unsigned field
cupsBytesPerLine actually is, instead of silently wrapping and handing
a too-small value downstream.
Verified by tracing header.cupsBytesPerLine's consumers (the
allocation at the cupsRasterOpen/row-buffer setup further down, and
the format_cmy/format_RGB write loops that iterate cupsWidth pixels
regardless of what cupsBytesPerLine says) to confirm all of them are
protected once this guard holds. No C build toolchain available
locally to compile-check.
Fixes OpenPrinting#184
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #184.
header.cupsBytesPerLinewas computed as:Both operands are unsigned 32-bit fields. A PPD offering an extreme RGB16 resolution together with a small, low-PPI image can drive
cupsWidthinto the tens of millions; multiplied by a wide pixel depth (e.g. 48 bits for RGB16), the product overflows 32-bit unsigned arithmetic and wraps to a small value before the+7/8rounds it down to bytes. The formatter (format_cmy/format_RGB) still writes a full row's worth of pixels, well past the undersized buffer that was allocated from the wrappedcupsBytesPerLine.Compute the row size in a wider type (
size_t, including theCUPS_ORDER_BANDEDmultiply, which could also push a borderline value over) and reject the page if it doesn't fit in the unsigned fieldcupsBytesPerLineactually is, instead of silently wrapping and handing a too-small value downstream.Verified: traced
header.cupsBytesPerLine's consumers (the allocation at the row-buffer setup, and theformat_cmy/format_RGBwrite loops that iteratecupsWidthpixels regardless of whatcupsBytesPerLinesays) to confirm all of them are protected once this guard holds. No C build toolchain available locally to compile-check.