[trunk] Speed-up opj_int_fix_mul by removing unneeded operation
[openjpeg.git] / src / lib / openjp2 / jp2.c
index 730d7f9d49fd48c0ecd5cb10ff026b2dc7815d38..3ee07af35f07218c288f9e67d36814ac13f66765 100644 (file)
@@ -1,11 +1,19 @@
 /*
- * Copyright (c) 2002-2007, Communications and Remote Sensing Laboratory, Universite catholique de Louvain (UCL), Belgium
- * Copyright (c) 2002-2007, Professor Benoit Macq
+ * The copyright in this software is being made available under the 2-clauses 
+ * BSD License, included below. This software may be subject to other third 
+ * party and contributor rights, including patent rights, and no such rights
+ * are granted under this license.
+ *
+ * Copyright (c) 2002-2014, Universite catholique de Louvain (UCL), Belgium
+ * Copyright (c) 2002-2014, Professor Benoit Macq
  * Copyright (c) 2001-2003, David Janssens
  * Copyright (c) 2002-2003, Yannick Verschueren
- * Copyright (c) 2003-2007, Francois-Olivier Devaux and Antonin Descampe
+ * Copyright (c) 2003-2007, Francois-Olivier Devaux 
+ * Copyright (c) 2003-2014, Antonin Descampe
  * Copyright (c) 2005, Herve Drolon, FreeImage Team
  * Copyright (c) 2010-2011, Kaori Hagihara
+ * Copyright (c) 2008, 2011-2012, Centre National d'Etudes Spatiales (CNES), FR 
+ * Copyright (c) 2012, CS Systemes d'Information, France
  * All rights reserved.
  *
  * Redistribution and use in source and binary forms, with or without
@@ -34,7 +42,7 @@
 /** @defgroup JP2 JP2 - JPEG-2000 file format reader/writer */
 /*@{*/
 
-#define BOX_SIZE       1024
+#define OPJ_BOX_SIZE   1024
 
 /** @name Local static functions */
 /*@{*/
@@ -100,6 +108,17 @@ static OPJ_BOOL opj_jp2_read_cdef( opj_jp2_t * jp2,
 
 static void opj_jp2_apply_cdef(opj_image_t *image, opj_jp2_color_t *color);
 
+/**
+ * Writes the Channel Definition box.
+ *
+ * @param jp2                                  jpeg2000 file codec.
+ * @param p_nb_bytes_written   pointer to store the nb of bytes written by the function.
+ *
+ * @return     the data being copied.
+ */
+static OPJ_BYTE * opj_jp2_write_cdef(   opj_jp2_t *jp2,
+                                                                                                                                                OPJ_UINT32 * p_nb_bytes_written );
+
 /**
  * Writes the Colour Specification box.
  *
@@ -426,12 +445,10 @@ static void opj_jp2_setup_decoding_validation (opj_jp2_t *jp2);
 static void opj_jp2_setup_header_reading (opj_jp2_t *jp2);
 
 /* ----------------------------------------------------------------------- */
-
  OPJ_BOOL opj_jp2_read_boxhdr(opj_jp2_box_t *box,
-                                    OPJ_UINT32 * p_number_bytes_read,
-                                    opj_stream_private_t *cio,
-                                    opj_event_mgr_t * p_manager
-                                    )
+                              OPJ_UINT32 * p_number_bytes_read,
+                              opj_stream_private_t *cio,
+                              opj_event_mgr_t * p_manager )
 {
        /* read header from file */
        OPJ_BYTE l_data_header [8];
@@ -442,7 +459,7 @@ static void opj_jp2_setup_header_reading (opj_jp2_t *jp2);
        assert(p_number_bytes_read != 00);
        assert(p_manager != 00);
 
-       *p_number_bytes_read = opj_stream_read_data(cio,l_data_header,8,p_manager);
+       *p_number_bytes_read = (OPJ_UINT32)opj_stream_read_data(cio,l_data_header,8,p_manager);
        if (*p_number_bytes_read != 8) {
                return OPJ_FALSE;
        }
@@ -450,13 +467,21 @@ static void opj_jp2_setup_header_reading (opj_jp2_t *jp2);
        /* process read data */
        opj_read_bytes(l_data_header,&(box->length), 4);
        opj_read_bytes(l_data_header+4,&(box->type), 4);
+    
+  if(box->length == 0)/* last box */
+    {
+    const OPJ_OFF_T bleft = opj_stream_get_number_byte_left(cio);
+    box->length = (OPJ_UINT32)bleft;
+    assert( (OPJ_OFF_T)box->length == bleft );
+    return OPJ_TRUE;
+    }
 
        /* do we have a "special very large box ?" */
        /* read then the XLBox */
        if (box->length == 1) {
                OPJ_UINT32 l_xl_part_size;
 
-               OPJ_UINT32 l_nb_bytes_read = opj_stream_read_data(cio,l_data_header,8,p_manager);
+               OPJ_UINT32 l_nb_bytes_read = (OPJ_UINT32)opj_stream_read_data(cio,l_data_header,8,p_manager);
                if (l_nb_bytes_read != 8) {
                        if (l_nb_bytes_read > 0) {
                                *p_number_bytes_read += l_nb_bytes_read;
@@ -465,14 +490,15 @@ static void opj_jp2_setup_header_reading (opj_jp2_t *jp2);
                        return OPJ_FALSE;
                }
 
+        *p_number_bytes_read = 16;
                opj_read_bytes(l_data_header,&l_xl_part_size, 4);
                if (l_xl_part_size != 0) {
                        opj_event_msg(p_manager, EVT_ERROR, "Cannot handle box sizes higher than 2^32\n");
                        return OPJ_FALSE;
                }
-               opj_read_bytes(l_data_header,&(box->length), 4);
+               opj_read_bytes(l_data_header+4,&(box->length), 4);
        }
-       return OPJ_TRUE;
+    return OPJ_TRUE;
 }
 
 #if 0
@@ -522,12 +548,11 @@ OPJ_BOOL opj_jp2_read_ihdr( opj_jp2_t *jp2,
        p_image_header_data += 2;
 
        /* allocate memory for components */
-       jp2->comps = (opj_jp2_comps_t*) opj_malloc(jp2->numcomps * sizeof(opj_jp2_comps_t));
+       jp2->comps = (opj_jp2_comps_t*) opj_calloc(jp2->numcomps, sizeof(opj_jp2_comps_t));
        if (jp2->comps == 0) {
                opj_event_msg(p_manager, EVT_ERROR, "Not enough memory to handle image header (ihdr)\n");
                return OPJ_FALSE;
        }
-       memset(jp2->comps,0,jp2->numcomps * sizeof(opj_jp2_comps_t));
 
        opj_read_bytes(p_image_header_data,&(jp2->bpc),1);                      /* BPC */
        ++ p_image_header_data;
@@ -559,11 +584,10 @@ OPJ_BYTE * opj_jp2_write_ihdr(opj_jp2_t *jp2,
        assert(p_nb_bytes_written != 00);
 
        /* default image header is 22 bytes wide */
-       l_ihdr_data = (OPJ_BYTE *) opj_malloc(22);
+       l_ihdr_data = (OPJ_BYTE *) opj_calloc(1,22);
        if (l_ihdr_data == 00) {
                return 00;
        }
-       memset(l_ihdr_data,0,22);
 
        l_current_ihdr_ptr = l_ihdr_data;
        
@@ -605,18 +629,17 @@ OPJ_BYTE * opj_jp2_write_bpcc(    opj_jp2_t *jp2,
 {
        OPJ_UINT32 i;
        /* room for 8 bytes for box and 1 byte for each component */
-       OPJ_INT32 l_bpcc_size = 8 + jp2->numcomps;
+       OPJ_UINT32 l_bpcc_size = 8 + jp2->numcomps;
        OPJ_BYTE * l_bpcc_data,* l_current_bpcc_ptr;
        
        /* preconditions */
        assert(jp2 != 00);
        assert(p_nb_bytes_written != 00);
 
-       l_bpcc_data = (OPJ_BYTE *) opj_malloc(l_bpcc_size);
+       l_bpcc_data = (OPJ_BYTE *) opj_calloc(1,l_bpcc_size);
        if (l_bpcc_data == 00) {
                return 00;
        }
-       memset(l_bpcc_data,0,l_bpcc_size);
 
        l_current_bpcc_ptr = l_bpcc_data;
 
@@ -668,6 +691,55 @@ OPJ_BOOL opj_jp2_read_bpcc( opj_jp2_t *jp2,
 
        return OPJ_TRUE;
 }
+static OPJ_BYTE * opj_jp2_write_cdef(opj_jp2_t *jp2, OPJ_UINT32 * p_nb_bytes_written)
+{
+       /* room for 8 bytes for box, 2 for n */
+       OPJ_UINT32 l_cdef_size = 10;
+       OPJ_BYTE * l_cdef_data,* l_current_cdef_ptr;
+       OPJ_UINT32 l_value;
+       OPJ_UINT16 i;
+
+       /* preconditions */
+       assert(jp2 != 00);
+       assert(p_nb_bytes_written != 00);
+       assert(jp2->color.jp2_cdef != 00);
+       assert(jp2->color.jp2_cdef->info != 00);
+       assert(jp2->color.jp2_cdef->n > 0U);
+
+       l_cdef_size += 6U * jp2->color.jp2_cdef->n;
+
+       l_cdef_data = (OPJ_BYTE *) opj_malloc(l_cdef_size);
+       if (l_cdef_data == 00) {
+               return 00;
+       }
+
+       l_current_cdef_ptr = l_cdef_data;
+       
+       opj_write_bytes(l_current_cdef_ptr,l_cdef_size,4);                      /* write box size */
+       l_current_cdef_ptr += 4;
+
+       opj_write_bytes(l_current_cdef_ptr,JP2_CDEF,4);                                 /* BPCC */
+       l_current_cdef_ptr += 4;
+
+       l_value = jp2->color.jp2_cdef->n;
+       opj_write_bytes(l_current_cdef_ptr,l_value,2);                                  /* N */
+       l_current_cdef_ptr += 2;
+
+       for (i = 0U; i < jp2->color.jp2_cdef->n; ++i) {
+               l_value = jp2->color.jp2_cdef->info[i].cn;
+               opj_write_bytes(l_current_cdef_ptr,l_value,2);                                  /* Cni */
+               l_current_cdef_ptr += 2;
+               l_value = jp2->color.jp2_cdef->info[i].typ;
+               opj_write_bytes(l_current_cdef_ptr,l_value,2);                                  /* Typi */
+               l_current_cdef_ptr += 2;
+               l_value = jp2->color.jp2_cdef->info[i].asoc;
+               opj_write_bytes(l_current_cdef_ptr,l_value,2);                                  /* Asoci */
+               l_current_cdef_ptr += 2;
+       }
+       *p_nb_bytes_written = l_cdef_size;
+
+       return l_cdef_data;
+}
 
 OPJ_BYTE * opj_jp2_write_colr(  opj_jp2_t *jp2,
                                                            OPJ_UINT32 * p_nb_bytes_written
@@ -676,27 +748,28 @@ OPJ_BYTE * opj_jp2_write_colr(  opj_jp2_t *jp2,
        /* room for 8 bytes for box 3 for common data and variable upon profile*/
        OPJ_UINT32 l_colr_size = 11;
        OPJ_BYTE * l_colr_data,* l_current_colr_ptr;
-       
+
        /* preconditions */
        assert(jp2 != 00);
        assert(p_nb_bytes_written != 00);
+    assert(jp2->meth == 1 || jp2->meth == 2);
 
-       switch (jp2->meth) {
+       switch (jp2->meth) { 
                case 1 :
-                       l_colr_size += 4;
+                       l_colr_size += 4; /* EnumCS */
                        break;
                case 2 :
-                       ++l_colr_size;
+            assert(jp2->color.icc_profile_len);        /* ICC profile */
+            l_colr_size += jp2->color.icc_profile_len;
                        break;
                default :
                        return 00;
        }
 
-       l_colr_data = (OPJ_BYTE *) opj_malloc(l_colr_size);
+       l_colr_data = (OPJ_BYTE *) opj_calloc(1,l_colr_size);
        if (l_colr_data == 00) {
                return 00;
        }
-       memset(l_colr_data,0,l_colr_size);
        
        l_current_colr_ptr = l_colr_data;
 
@@ -715,11 +788,16 @@ OPJ_BYTE * opj_jp2_write_colr(  opj_jp2_t *jp2,
        opj_write_bytes(l_current_colr_ptr, jp2->approx,1);                             /* APPROX */
        ++l_current_colr_ptr;
        
-       if (jp2->meth == 1) {
-               opj_write_bytes(l_current_colr_ptr, jp2->enumcs,4);                     /* EnumCS */
-       }
-       else {
-               opj_write_bytes(l_current_colr_ptr, 0, 1);                                      /* PROFILE (??) */
+       if (jp2->meth == 1) { /* Meth value is restricted to 1 or 2 (Table I.9 of part 1) */
+        opj_write_bytes(l_current_colr_ptr, jp2->enumcs,4); }       /* EnumCS */
+    else {
+        if (jp2->meth == 2) {                                      /* ICC profile */
+            OPJ_UINT32 i;
+            for(i = 0; i < jp2->color.icc_profile_len; ++i) {
+                opj_write_bytes(l_current_colr_ptr, jp2->color.icc_profile_buf[i], 1);
+                ++l_current_colr_ptr;
+            }
+        }
        }
 
        *p_nb_bytes_written = l_colr_size;
@@ -738,6 +816,107 @@ void opj_jp2_free_pclr(opj_jp2_color_t *color)
     opj_free(color->jp2_pclr); color->jp2_pclr = NULL;
 }
 
+static OPJ_BOOL opj_jp2_check_color(opj_image_t *image, opj_jp2_color_t *color, opj_event_mgr_t *p_manager)
+{
+       OPJ_UINT16 i;
+
+       /* testcase 4149.pdf.SIGSEGV.cf7.3501 */
+       if (color->jp2_cdef) {
+               opj_jp2_cdef_info_t *info = color->jp2_cdef->info;
+               OPJ_UINT16 n = color->jp2_cdef->n;
+               OPJ_UINT32 nr_channels = image->numcomps; /* FIXME image->numcomps == jp2->numcomps before color is applied ??? */
+
+               /* cdef applies to cmap channels if any */
+               if (color->jp2_pclr && color->jp2_pclr->cmap) {
+                       nr_channels = (OPJ_UINT32)color->jp2_pclr->nr_channels;
+               }
+
+               for (i = 0; i < n; i++) {
+                       if (info[i].cn >= nr_channels) {
+                               opj_event_msg(p_manager, EVT_ERROR, "Invalid component index %d (>= %d).\n", info[i].cn, nr_channels);
+                               return OPJ_FALSE;
+                       }
+                       if (info[i].asoc > 0 && (OPJ_UINT32)(info[i].asoc - 1) >= nr_channels) {
+                               opj_event_msg(p_manager, EVT_ERROR, "Invalid component index %d (>= %d).\n", info[i].asoc - 1, nr_channels);
+                               return OPJ_FALSE;
+                       }
+               }
+
+               /* issue 397 */
+               /* ISO 15444-1 states that if cdef is present, it shall contain a complete list of channel definitions. */
+               while (nr_channels > 0)
+               {
+                       for(i = 0; i < n; ++i) {
+                               if ((OPJ_UINT32)info[i].cn == (nr_channels - 1U)) {
+                                       break;
+                               }
+                       }
+                       if (i == n) {
+                               opj_event_msg(p_manager, EVT_ERROR, "Incomplete channel definitions.\n");
+                               return OPJ_FALSE;
+                       }
+                       --nr_channels;
+               }
+       }
+
+       /* testcases 451.pdf.SIGSEGV.f4c.3723, 451.pdf.SIGSEGV.5b5.3723 and
+          66ea31acbb0f23a2bbc91f64d69a03f5_signal_sigsegv_13937c0_7030_5725.pdf */
+       if (color->jp2_pclr && color->jp2_pclr->cmap) {
+               OPJ_UINT16 nr_channels = color->jp2_pclr->nr_channels;
+               opj_jp2_cmap_comp_t *cmap = color->jp2_pclr->cmap;
+               OPJ_BOOL *pcol_usage, is_sane = OPJ_TRUE;
+
+               /* verify that all original components match an existing one */
+               for (i = 0; i < nr_channels; i++) {
+                       if (cmap[i].cmp >= image->numcomps) {
+                               opj_event_msg(p_manager, EVT_ERROR, "Invalid component index %d (>= %d).\n", cmap[i].cmp, image->numcomps);
+                               is_sane = OPJ_FALSE;
+                       }
+               }
+
+               pcol_usage = opj_calloc(nr_channels, sizeof(OPJ_BOOL));
+               if (!pcol_usage) {
+                       opj_event_msg(p_manager, EVT_ERROR, "Unexpected OOM.\n");
+                       return OPJ_FALSE;
+               }
+               /* verify that no component is targeted more than once */
+               for (i = 0; i < nr_channels; i++) {
+      OPJ_UINT16 pcol = cmap[i].pcol;
+      assert(cmap[i].mtyp == 0 || cmap[i].mtyp == 1);
+                       if (pcol >= nr_channels) {
+                               opj_event_msg(p_manager, EVT_ERROR, "Invalid component/palette index for direct mapping %d.\n", pcol);
+                               is_sane = OPJ_FALSE;
+                       }
+                       else if (pcol_usage[pcol] && cmap[i].mtyp == 1) {
+                               opj_event_msg(p_manager, EVT_ERROR, "Component %d is mapped twice.\n", pcol);
+                               is_sane = OPJ_FALSE;
+                       }
+      else if (cmap[i].mtyp == 0 && cmap[i].pcol != 0) {
+        /* I.5.3.5 PCOL: If the value of the MTYP field for this channel is 0, then
+         * the value of this field shall be 0. */
+                               opj_event_msg(p_manager, EVT_ERROR, "Direct use at #%d however pcol=%d.\n", i, pcol);
+                               is_sane = OPJ_FALSE;
+      }
+                       else
+                               pcol_usage[pcol] = OPJ_TRUE;
+               }
+               /* verify that all components are targeted at least once */
+               for (i = 0; i < nr_channels; i++) {
+                       if (!pcol_usage[i] && cmap[i].mtyp != 0) {
+                               opj_event_msg(p_manager, EVT_ERROR, "Component %d doesn't have a mapping.\n", i);
+                               is_sane = OPJ_FALSE;
+                       }
+               }
+               opj_free(pcol_usage);
+               if (!is_sane) {
+                       return OPJ_FALSE;
+               }
+       }
+
+       return OPJ_TRUE;
+}
+
+/* file9.jp2 */
 void opj_jp2_apply_pclr(opj_image_t *image, opj_jp2_color_t *color)
 {
        opj_image_comp_t *old_comps, *new_comps;
@@ -758,44 +937,67 @@ void opj_jp2_apply_pclr(opj_image_t *image, opj_jp2_color_t *color)
        old_comps = image->comps;
        new_comps = (opj_image_comp_t*)
                        opj_malloc(nr_channels * sizeof(opj_image_comp_t));
-
+       if (!new_comps) {
+               /* FIXME no error code for opj_jp2_apply_pclr */
+               /* FIXME event manager error callback */
+               return;
+       }
        for(i = 0; i < nr_channels; ++i) {
                pcol = cmap[i].pcol; cmp = cmap[i].cmp;
 
-               new_comps[pcol] = old_comps[cmp];
-
                /* Direct use */
-               if(cmap[i].mtyp == 0){
-                       old_comps[cmp].data = NULL; continue;
-               }
+    if(cmap[i].mtyp == 0){
+      assert( pcol == 0 );
+      new_comps[i] = old_comps[cmp];
+    } else {
+      assert( i == pcol );
+      new_comps[pcol] = old_comps[cmp];
+    }
 
                /* Palette mapping: */
-               new_comps[pcol].data = (OPJ_INT32*)
+               new_comps[i].data = (OPJ_INT32*)
                                opj_malloc(old_comps[cmp].w * old_comps[cmp].h * sizeof(OPJ_INT32));
-               new_comps[pcol].prec = channel_size[i];
-               new_comps[pcol].sgnd = channel_sign[i];
+               if (!new_comps[i].data) {
+                       opj_free(new_comps);
+                       new_comps = NULL;
+                       /* FIXME no error code for opj_jp2_apply_pclr */
+                       /* FIXME event manager error callback */
+                       return;
+               }
+               new_comps[i].prec = channel_size[i];
+               new_comps[i].sgnd = channel_sign[i];
        }
 
        top_k = color->jp2_pclr->nr_entries - 1;
 
        for(i = 0; i < nr_channels; ++i) {
-               /* Direct use: */
-               if(cmap[i].mtyp == 0) continue;
-
                /* Palette mapping: */
                cmp = cmap[i].cmp; pcol = cmap[i].pcol;
                src = old_comps[cmp].data;
-               dst = new_comps[pcol].data;
+    assert( src );
                max = new_comps[pcol].w * new_comps[pcol].h;
 
-               for(j = 0; j < max; ++j)
-               {
-                       /* The index */
-                       if((k = src[j]) < 0) k = 0; else if(k > top_k) k = top_k;
-
-                       /* The colour */
-                       dst[j] = entries[k * nr_channels + pcol];
-               }
+               /* Direct use: */
+    if(cmap[i].mtyp == 0) {
+      assert( cmp == 0 );
+      dst = new_comps[i].data;
+      assert( dst );
+      for(j = 0; j < max; ++j) {
+        dst[j] = src[j];
+      }
+    }
+    else {
+      assert( i == pcol );
+      dst = new_comps[pcol].data;
+      assert( dst );
+      for(j = 0; j < max; ++j) {
+        /* The index */
+        if((k = src[j]) < 0) k = 0; else if(k > top_k) k = top_k;
+
+        /* The colour */
+        dst[j] = (OPJ_INT32)entries[k * nr_channels + pcol];
+        }
+    }
        }
 
        max = image->numcomps;
@@ -823,6 +1025,7 @@ OPJ_BOOL opj_jp2_read_pclr(        opj_jp2_t *jp2,
        OPJ_UINT16 nr_entries,nr_channels;
        OPJ_UINT16 i, j;
        OPJ_UINT32 l_value;
+       OPJ_BYTE *orig_header_data = p_pclr_header_data;
 
        /* preconditions */
        assert(p_pclr_header_data != 00);
@@ -833,15 +1036,29 @@ OPJ_BOOL opj_jp2_read_pclr(      opj_jp2_t *jp2,
        if(jp2->color.jp2_pclr)
                return OPJ_FALSE;
 
+       if (p_pclr_header_size < 3)
+               return OPJ_FALSE;
+
        opj_read_bytes(p_pclr_header_data, &l_value , 2);       /* NE */
        p_pclr_header_data += 2;
        nr_entries = (OPJ_UINT16) l_value;
+       if ((nr_entries == 0U) || (nr_entries > 1024U)) {
+               opj_event_msg(p_manager, EVT_ERROR, "Invalid PCLR box. Reports %d entries\n", (int)nr_entries);
+               return OPJ_FALSE;
+       }
 
        opj_read_bytes(p_pclr_header_data, &l_value , 1);       /* NPC */
        ++p_pclr_header_data;
        nr_channels = (OPJ_UINT16) l_value;
+       if (nr_channels == 0U) {
+               opj_event_msg(p_manager, EVT_ERROR, "Invalid PCLR box. Reports 0 palette columns\n");
+               return OPJ_FALSE;
+       }
 
-       entries = (OPJ_UINT32*) opj_malloc(nr_channels * nr_entries * sizeof(OPJ_UINT32));
+       if (p_pclr_header_size < 3 + (OPJ_UINT32)nr_channels)
+               return OPJ_FALSE;
+
+       entries = (OPJ_UINT32*) opj_malloc((size_t)nr_channels * nr_entries * sizeof(OPJ_UINT32));
     if (!entries)
         return OPJ_FALSE;
        channel_size = (OPJ_BYTE*) opj_malloc(nr_channels);
@@ -880,13 +1097,18 @@ OPJ_BOOL opj_jp2_read_pclr(      opj_jp2_t *jp2,
                opj_read_bytes(p_pclr_header_data, &l_value , 1);       /* Bi */
                ++p_pclr_header_data;
 
-               channel_size[i] = (l_value & 0x7f) + 1;
-               channel_sign[i] = (l_value & 0x80)? 1 : 0;
+               channel_size[i] = (OPJ_BYTE)((l_value & 0x7f) + 1);
+               channel_sign[i] = (l_value & 0x80) ? 1 : 0;
        }
 
        for(j = 0; j < nr_entries; ++j) {
                for(i = 0; i < nr_channels; ++i) {
-                       OPJ_INT32 bytes_to_read = (channel_size[i]+7)>>3;
+                       OPJ_UINT32 bytes_to_read = (OPJ_UINT32)((channel_size[i]+7)>>3);
+
+                       if (bytes_to_read > sizeof(OPJ_UINT32))
+                               bytes_to_read = sizeof(OPJ_UINT32);
+                       if ((ptrdiff_t)p_pclr_header_size < (ptrdiff_t)(p_pclr_header_data - orig_header_data) + (ptrdiff_t)bytes_to_read)
+                               return OPJ_FALSE;
 
                        opj_read_bytes(p_pclr_header_data, &l_value , bytes_to_read);   /* Cji */
                        p_pclr_header_data += bytes_to_read;
@@ -929,6 +1151,11 @@ OPJ_BOOL opj_jp2_read_cmap(       opj_jp2_t * jp2,
        }
 
        nr_channels = jp2->color.jp2_pclr->nr_channels;
+       if (p_cmap_header_size < (OPJ_UINT32)nr_channels * 4) {
+               opj_event_msg(p_manager, EVT_ERROR, "Insufficient data for CMAP box.\n");
+               return OPJ_FALSE;
+       }
+
        cmap = (opj_jp2_cmap_comp_t*) opj_malloc(nr_channels * sizeof(opj_jp2_cmap_comp_t));
     if (!cmap)
         return OPJ_FALSE;
@@ -957,35 +1184,64 @@ void opj_jp2_apply_cdef(opj_image_t *image, opj_jp2_color_t *color)
 {
        opj_jp2_cdef_info_t *info;
        OPJ_UINT16 i, n, cn, asoc, acn;
-
+       
        info = color->jp2_cdef->info;
        n = color->jp2_cdef->n;
-
+       
        for(i = 0; i < n; ++i)
        {
                /* WATCH: acn = asoc - 1 ! */
-               if((asoc = info[i].asoc) == 0) continue;
-
-               cn = info[i].cn; 
-        acn = asoc - 1;
-
-               if(cn != acn)
+               asoc = info[i].asoc;
+               cn = info[i].cn;
+               
+               if( cn >= image->numcomps)
+               {
+                       fprintf(stderr, "cn=%d, numcomps=%d\n", cn, image->numcomps);
+                       continue;
+               }
+               if(asoc == 0 || asoc == 65535)
+               {
+                       image->comps[cn].alpha = info[i].typ;
+                       continue;
+               }
+               
+               acn = (OPJ_UINT16)(asoc - 1);
+               if( acn >= image->numcomps )
+               {
+                       fprintf(stderr, "acn=%d, numcomps=%d\n", acn, image->numcomps);
+                       continue;
+               }
+               
+               /* Swap only if color channel */
+               if((cn != acn) && (info[i].typ == 0))
                {
                        opj_image_comp_t saved;
-
+                       OPJ_UINT16 j;
+                       
                        memcpy(&saved, &image->comps[cn], sizeof(opj_image_comp_t));
                        memcpy(&image->comps[cn], &image->comps[acn], sizeof(opj_image_comp_t));
                        memcpy(&image->comps[acn], &saved, sizeof(opj_image_comp_t));
-
-                       info[i].asoc = cn + 1;
-                       info[acn].asoc = info[acn].cn + 1;
+                       
+                       /* Swap channels in following channel definitions, don't bother with j <= i that are already processed */
+                       for (j = (OPJ_UINT16)(i + 1U); j < n ; ++j)
+                       {
+                               if (info[j].cn == cn) {
+                                       info[j].cn = acn;
+                               }
+                               else if (info[j].cn == acn) {
+                                       info[j].cn = cn;
+                               }
+                               /* asoc is related to color index. Do not update. */
+                       }
                }
+               
+               image->comps[cn].alpha = info[i].typ;
        }
-
+       
        if(color->jp2_cdef->info) opj_free(color->jp2_cdef->info);
-
+       
        opj_free(color->jp2_cdef); color->jp2_cdef = NULL;
-
+       
 }/* jp2_apply_cdef() */
 
 OPJ_BOOL opj_jp2_read_cdef(    opj_jp2_t * jp2,
@@ -1008,6 +1264,11 @@ OPJ_BOOL opj_jp2_read_cdef(      opj_jp2_t * jp2,
         * inside a JP2 Header box.'*/
        if(jp2->color.jp2_cdef) return OPJ_FALSE;
 
+       if (p_cdef_header_size < 2) {
+               opj_event_msg(p_manager, EVT_ERROR, "Insufficient data for CDEF box.\n");
+               return OPJ_FALSE;
+       }
+
        opj_read_bytes(p_cdef_header_data,&l_value ,2);                 /* N */
        p_cdef_header_data+= 2;
 
@@ -1016,6 +1277,11 @@ OPJ_BOOL opj_jp2_read_cdef(      opj_jp2_t * jp2,
                return OPJ_FALSE;
        }
 
+       if (p_cdef_header_size < 2 + (OPJ_UINT32)(OPJ_UINT16)l_value * 6) {
+               opj_event_msg(p_manager, EVT_ERROR, "Insufficient data for CDEF box.\n");
+               return OPJ_FALSE;
+       }
+
        cdef_info = (opj_jp2_cdef_info_t*) opj_malloc(l_value * sizeof(opj_jp2_cdef_info_t));
     if (!cdef_info)
         return OPJ_FALSE;
@@ -1083,26 +1349,31 @@ OPJ_BOOL opj_jp2_read_colr( opj_jp2_t *jp2,
        ++p_colr_header_data;
 
        if (jp2->meth == 1) {
-               if (p_colr_header_size != 7) {
-                       opj_event_msg(p_manager, EVT_ERROR, "Bad BPCC header box (bad size)\n");
+               if (p_colr_header_size < 7) {
+                       opj_event_msg(p_manager, EVT_ERROR, "Bad COLR header box (bad size: %d)\n", p_colr_header_size);
                        return OPJ_FALSE;
                }
+               if (p_colr_header_size > 7) {
+                       /* testcase Altona_Technical_v20_x4.pdf */
+                       opj_event_msg(p_manager, EVT_WARNING, "Bad COLR header box (bad size: %d)\n", p_colr_header_size);
+               }
 
                opj_read_bytes(p_colr_header_data,&jp2->enumcs ,4);                     /* EnumCS */
+        
+        jp2->color.jp2_has_colr = 1;
        }
        else if (jp2->meth == 2) {
                /* ICC profile */
                OPJ_INT32 it_icc_value = 0;
-               OPJ_INT32 icc_len = p_colr_header_size - 3;
+               OPJ_INT32 icc_len = (OPJ_INT32)p_colr_header_size - 3;
 
-               jp2->color.icc_profile_len = icc_len;
-               jp2->color.icc_profile_buf = (OPJ_BYTE*) opj_malloc(icc_len);
+               jp2->color.icc_profile_len = (OPJ_UINT32)icc_len;
+               jp2->color.icc_profile_buf = (OPJ_BYTE*) opj_calloc(1,(size_t)icc_len);
         if (!jp2->color.icc_profile_buf)
         {
             jp2->color.icc_profile_len = 0;
             return OPJ_FALSE;
         }
-               memset(jp2->color.icc_profile_buf, 0, icc_len * sizeof(OPJ_BYTE));
 
                for (it_icc_value = 0; it_icc_value < icc_len; ++it_icc_value)
                {
@@ -1110,14 +1381,17 @@ OPJ_BOOL opj_jp2_read_colr( opj_jp2_t *jp2,
                        ++p_colr_header_data;
                        jp2->color.icc_profile_buf[it_icc_value] = (OPJ_BYTE) l_value;
                }
-
+           
+        jp2->color.jp2_has_colr = 1;
        }
-       else 
-               opj_event_msg(p_manager, EVT_INFO, "COLR BOX meth value is not a regular value (%d), so we will skip the fields following the approx field.\n", jp2->meth);
-
-       jp2->color.jp2_has_colr = 1;
-
-       return OPJ_TRUE;
+       else if (jp2->meth > 2)
+    {
+        /*     ISO/IEC 15444-1:2004 (E), Table I.9 Legal METH values:
+        conforming JP2 reader shall ignore the entire Colour Specification box.*/
+        opj_event_msg(p_manager, EVT_INFO, "COLR BOX meth value is not a regular value (%d), " 
+            "so we will ignore the entire Colour Specification box. \n", jp2->meth);
+    }
+    return OPJ_TRUE;
 }
 
 OPJ_BOOL opj_jp2_decode(opj_jp2_t *jp2,
@@ -1135,6 +1409,9 @@ OPJ_BOOL opj_jp2_decode(opj_jp2_t *jp2,
        }
 
     if (!jp2->ignore_pclr_cmap_cdef){
+           if (!opj_jp2_check_color(p_image, &(jp2->color), p_manager)) {
+                   return OPJ_FALSE;
+           }
 
            /* Set Image Color Space */
            if (jp2->enumcs == 16)
@@ -1143,14 +1420,11 @@ OPJ_BOOL opj_jp2_decode(opj_jp2_t *jp2,
                    p_image->color_space = OPJ_CLRSPC_GRAY;
            else if (jp2->enumcs == 18)
                    p_image->color_space = OPJ_CLRSPC_SYCC;
+            else if (jp2->enumcs == 24)
+                    p_image->color_space = OPJ_CLRSPC_EYCC;
            else
                    p_image->color_space = OPJ_CLRSPC_UNKNOWN;
 
-           /* Apply the color space if needed */
-           if(jp2->color.jp2_cdef) {
-                   opj_jp2_apply_cdef(p_image, &(jp2->color));
-           }
-
            if(jp2->color.jp2_pclr) {
                    /* Part 1, I.5.3.4: Either both or none : */
                    if( !jp2->color.jp2_pclr->cmap)
@@ -1159,6 +1433,11 @@ OPJ_BOOL opj_jp2_decode(opj_jp2_t *jp2,
                            opj_jp2_apply_pclr(p_image, &(jp2->color));
            }
 
+           /* Apply the color space if needed */
+           if(jp2->color.jp2_cdef) {
+                   opj_jp2_apply_cdef(p_image, &(jp2->color));
+           }
+
            if(jp2->color.icc_profile_buf) {
                    p_image->icc_profile_buf = jp2->color.icc_profile_buf;
                    p_image->icc_profile_len = jp2->color.icc_profile_len;
@@ -1174,12 +1453,12 @@ OPJ_BOOL opj_jp2_write_jp2h(opj_jp2_t *jp2,
                             opj_event_mgr_t * p_manager
                             )
 {
-       opj_jp2_img_header_writer_handler_t l_writers [3];
+       opj_jp2_img_header_writer_handler_t l_writers [4];
        opj_jp2_img_header_writer_handler_t * l_current_writer;
 
        OPJ_INT32 i, l_nb_pass;
        /* size of data for super box*/
-       OPJ_INT32 l_jp2h_size = 8;
+       OPJ_UINT32 l_jp2h_size = 8;
        OPJ_BOOL l_result = OPJ_TRUE;
 
        /* to store the data of the super box */
@@ -1204,6 +1483,11 @@ OPJ_BOOL opj_jp2_write_jp2h(opj_jp2_t *jp2,
                l_writers[1].handler = opj_jp2_write_colr;
        }
        
+       if (jp2->color.jp2_cdef != NULL) {
+               l_writers[l_nb_pass].handler = opj_jp2_write_cdef;
+               l_nb_pass++;
+       }
+       
        /* write box header */
        /* write JP2H type */
        opj_write_bytes(l_jp2h_data+4,JP2_JP2H,4);
@@ -1281,15 +1565,13 @@ OPJ_BOOL opj_jp2_write_ftyp(opj_jp2_t *jp2,
        assert(jp2 != 00);
        assert(p_manager != 00);
 
-       l_ftyp_data = (OPJ_BYTE *) opj_malloc(l_ftyp_size);
+       l_ftyp_data = (OPJ_BYTE *) opj_calloc(1,l_ftyp_size);
        
        if (l_ftyp_data == 00) {
                opj_event_msg(p_manager, EVT_ERROR, "Not enough memory to handle ftyp data\n");
                return OPJ_FALSE;
        }
 
-       memset(l_ftyp_data,0,l_ftyp_size);
-
        l_current_data_ptr = l_ftyp_data;
 
        opj_write_bytes(l_current_data_ptr, l_ftyp_size,4); /* box size */
@@ -1400,16 +1682,21 @@ void opj_jp2_setup_decoder(opj_jp2_t *jp2, opj_dparameters_t *parameters)
 /* JP2 encoder interface                                             */
 /* ----------------------------------------------------------------------- */
 
-void opj_jp2_setup_encoder(    opj_jp2_t *jp2,
+OPJ_BOOL opj_jp2_setup_encoder(        opj_jp2_t *jp2,
                             opj_cparameters_t *parameters,
                             opj_image_t *image,
                             opj_event_mgr_t * p_manager)
 {
-    OPJ_UINT32 i;
-       OPJ_INT32 depth_0, sign;
+       OPJ_UINT32 i;
+       OPJ_UINT32 depth_0;
+  OPJ_UINT32 sign;
+       OPJ_UINT32 alpha_count;
+       OPJ_UINT32 color_channels = 0U;
+       OPJ_UINT32 alpha_channel = 0U;
+       
 
        if(!jp2 || !parameters || !image)
-               return;
+               return OPJ_FALSE;
 
        /* setup the J2K codec */
        /* ------------------- */
@@ -1417,10 +1704,12 @@ void opj_jp2_setup_encoder(     opj_jp2_t *jp2,
        /* Check if number of components respects standard */
        if (image->numcomps < 1 || image->numcomps > 16384) {
                opj_event_msg(p_manager, EVT_ERROR, "Invalid number of components specified while setting up JP2 encoder\n");
-               return;
+               return OPJ_FALSE;
        }
 
-       opj_j2k_setup_encoder(jp2->j2k, parameters, image, p_manager );
+       if (opj_j2k_setup_encoder(jp2->j2k, parameters, image, p_manager ) == OPJ_FALSE) {
+               return OPJ_FALSE;
+       }
 
        /* setup the JP2 codec */
        /* ------------------- */
@@ -1431,22 +1720,23 @@ void opj_jp2_setup_encoder(     opj_jp2_t *jp2,
        jp2->minversion = 0;    /* MinV */
        jp2->numcl = 1;
        jp2->cl = (OPJ_UINT32*) opj_malloc(jp2->numcl * sizeof(OPJ_UINT32));
-    if (!jp2->cl){
-        jp2->cl = NULL;
-        opj_event_msg(p_manager, EVT_ERROR, "Not enough memory when setup the JP2 encoder\n");
-        return;
-    }
+       if (!jp2->cl){
+               jp2->cl = NULL;
+               opj_event_msg(p_manager, EVT_ERROR, "Not enough memory when setup the JP2 encoder\n");
+               return OPJ_FALSE;
+       }
        jp2->cl[0] = JP2_JP2;   /* CL0 : JP2 */
 
        /* Image Header box */
 
        jp2->numcomps = image->numcomps;        /* NC */
        jp2->comps = (opj_jp2_comps_t*) opj_malloc(jp2->numcomps * sizeof(opj_jp2_comps_t));
-    if (!jp2->comps) {
-        jp2->comps = NULL;
-        opj_event_msg(p_manager, EVT_ERROR, "Not enough memory when setup the JP2 encoder\n");
-        return;
-    }
+       if (!jp2->comps) {
+               jp2->comps = NULL;
+               opj_event_msg(p_manager, EVT_ERROR, "Not enough memory when setup the JP2 encoder\n");
+               /* Memory of jp2->cl will be freed by opj_jp2_destroy */
+               return OPJ_FALSE;
+       }
 
        jp2->h = image->y1 - image->y0;         /* HEIGHT */
        jp2->w = image->x1 - image->x0;         /* WIDTH */
@@ -1455,7 +1745,7 @@ void opj_jp2_setup_encoder(       opj_jp2_t *jp2,
        sign = image->comps[0].sgnd;
        jp2->bpc = depth_0 + (sign << 7);
        for (i = 1; i < image->numcomps; i++) {
-               OPJ_INT32 depth = image->comps[i].prec - 1;
+               OPJ_UINT32 depth = image->comps[i].prec - 1;
                sign = image->comps[i].sgnd;
                if (depth_0 != depth)
                        jp2->bpc = 255;
@@ -1470,32 +1760,102 @@ void opj_jp2_setup_encoder(    opj_jp2_t *jp2,
        }
 
        /* Colour Specification box */
-       if ((image->numcomps == 1 || image->numcomps == 3) && (jp2->bpc != 255)) {
-               jp2->meth = 1;  /* METH: Enumerated colourspace */
-       } else {
-               jp2->meth = 2;  /* METH: Restricted ICC profile */
+    if(image->icc_profile_len) {
+        jp2->meth = 2;
+        jp2->enumcs = 0;
+    } 
+    else {
+        jp2->meth = 1;
+        if (image->color_space == 1)
+            jp2->enumcs = 16;  /* sRGB as defined by IEC 61966-2-1 */
+        else if (image->color_space == 2)
+            jp2->enumcs = 17;  /* greyscale */
+        else if (image->color_space == 3)
+            jp2->enumcs = 18;  /* YUV */
+    }
+
+       /* Channel Definition box */
+       /* FIXME not provided by parameters */
+       /* We try to do what we can... */
+       alpha_count = 0U;
+       for (i = 0; i < image->numcomps; i++) {
+               if (image->comps[i].alpha != 0) {
+                       alpha_count++;
+                       alpha_channel = i;
+               }
        }
-       if (jp2->meth == 1) {
-               if (image->color_space == 1)
-                       jp2->enumcs = 16;       /* sRGB as defined by IEC 61966-2-1 */
-               else if (image->color_space == 2)
-                       jp2->enumcs = 17;       /* greyscale */
-               else if (image->color_space == 3)
-                       jp2->enumcs = 18;       /* YUV */
-       } else {
-               jp2->enumcs = 0;                /* PROFILE (??) */
+       if (alpha_count == 1U) { /* no way to deal with more than 1 alpha channel */
+               switch (jp2->enumcs) {
+                       case 16:
+                       case 18:
+                               color_channels = 3;
+                               break;
+                       case 17:
+                               color_channels = 1;
+                               break;
+                       default:
+                               alpha_count = 0U;
+                               break;
+               }
+               if (alpha_count == 0U) {
+                       opj_event_msg(p_manager, EVT_WARNING, "Alpha channel specified but unknown enumcs. No cdef box will be created.\n");
+               } else if (image->numcomps < (color_channels+1)) {
+                       opj_event_msg(p_manager, EVT_WARNING, "Alpha channel specified but not enough image components for an automatic cdef box creation.\n");
+                       alpha_count = 0U;
+               } else if ((OPJ_UINT32)alpha_channel < color_channels) {
+                       opj_event_msg(p_manager, EVT_WARNING, "Alpha channel position conflicts with color channel. No cdef box will be created.\n");
+                       alpha_count = 0U;
+               }
+       } else if (alpha_count > 1) {
+               opj_event_msg(p_manager, EVT_WARNING, "Multiple alpha channels specified. No cdef box will be created.\n");
+       }
+       if (alpha_count == 1U) { /* if here, we know what we can do */
+               jp2->color.jp2_cdef = (opj_jp2_cdef_t*)opj_malloc(sizeof(opj_jp2_cdef_t));
+               if(!jp2->color.jp2_cdef) {
+                       opj_event_msg(p_manager, EVT_ERROR, "Not enough memory to setup the JP2 encoder\n");
+                       return OPJ_FALSE;
+               }
+               /* no memset needed, all values will be overwritten except if jp2->color.jp2_cdef->info allocation fails, */
+               /* in which case jp2->color.jp2_cdef->info will be NULL => valid for destruction */
+               jp2->color.jp2_cdef->info = (opj_jp2_cdef_info_t*) opj_malloc(image->numcomps * sizeof(opj_jp2_cdef_info_t));
+               if (!jp2->color.jp2_cdef->info) {
+                       /* memory will be freed by opj_jp2_destroy */
+                       opj_event_msg(p_manager, EVT_ERROR, "Not enough memory to setup the JP2 encoder\n");
+                       return OPJ_FALSE;
+               }
+               jp2->color.jp2_cdef->n = (OPJ_UINT16) image->numcomps; /* cast is valid : image->numcomps [1,16384] */
+               for (i = 0U; i < color_channels; i++) {
+                       jp2->color.jp2_cdef->info[i].cn = (OPJ_UINT16)i; /* cast is valid : image->numcomps [1,16384] */
+                       jp2->color.jp2_cdef->info[i].typ = 0U;
+                       jp2->color.jp2_cdef->info[i].asoc = (OPJ_UINT16)(i+1U); /* No overflow + cast is valid : image->numcomps [1,16384] */
+               }
+               for (; i < image->numcomps; i++) {
+                       if (image->comps[i].alpha != 0) { /* we'll be here exactly once */
+                               jp2->color.jp2_cdef->info[i].cn = (OPJ_UINT16)i; /* cast is valid : image->numcomps [1,16384] */
+                               jp2->color.jp2_cdef->info[i].typ = 1U; /* Opacity channel */
+                               jp2->color.jp2_cdef->info[i].asoc = 0U; /* Apply alpha channel to the whole image */
+                       } else {
+                               /* Unknown channel */
+                               jp2->color.jp2_cdef->info[i].cn = (OPJ_UINT16)i; /* cast is valid : image->numcomps [1,16384] */
+                               jp2->color.jp2_cdef->info[i].typ = 65535U;
+                               jp2->color.jp2_cdef->info[i].asoc = 65535U;
+                       }
+               }
        }
+
        jp2->precedence = 0;    /* PRECEDENCE */
        jp2->approx = 0;                /* APPROX */
 
        jp2->jpip_on = parameters->jpip_on;
+
+       return OPJ_TRUE;
 }
 
 OPJ_BOOL opj_jp2_encode(opj_jp2_t *jp2,
                                                opj_stream_private_t *stream,
                                                opj_event_mgr_t * p_manager)
 {
-       return opj_j2k_encode_v2(jp2->j2k, stream, p_manager);
+       return opj_j2k_encode(jp2->j2k, stream, p_manager);
 }
 
 OPJ_BOOL opj_jp2_end_decompress(opj_jp2_t *jp2,
@@ -1630,7 +1990,7 @@ OPJ_BOOL opj_jp2_read_header_procedure(  opj_jp2_t *jp2,
        opj_jp2_box_t box;
        OPJ_UINT32 l_nb_bytes_read;
        const opj_jp2_header_handler_t * l_current_handler;
-       OPJ_UINT32 l_last_data_size = BOX_SIZE;
+       OPJ_UINT32 l_last_data_size = OPJ_BOX_SIZE;
        OPJ_UINT32 l_current_data_size;
        OPJ_BYTE * l_current_data = 00;
 
@@ -1639,13 +1999,12 @@ OPJ_BOOL opj_jp2_read_header_procedure(  opj_jp2_t *jp2,
        assert(jp2 != 00);
        assert(p_manager != 00);
 
-       l_current_data = (OPJ_BYTE*)opj_malloc(l_last_data_size);
+       l_current_data = (OPJ_BYTE*)opj_calloc(1,l_last_data_size);
 
        if (l_current_data == 00) {
                opj_event_msg(p_manager, EVT_ERROR, "Not enough memory to handle jpeg2000 file header\n");
                return OPJ_FALSE;
        }
-       memset(l_current_data, 0 , l_last_data_size);
 
        while (opj_jp2_read_boxhdr(&box,&l_nb_bytes_read,stream,p_manager)) {
                /* is it the codestream box ? */
@@ -1666,14 +2025,26 @@ OPJ_BOOL opj_jp2_read_header_procedure(  opj_jp2_t *jp2,
                        opj_free(l_current_data);
                        return OPJ_FALSE;
                }
+               /* testcase 1851.pdf.SIGSEGV.ce9.948 */
+        else if (box.length < l_nb_bytes_read) {
+                       opj_event_msg(p_manager, EVT_ERROR, "invalid box size %d (%x)\n", box.length, box.type);
+                       opj_free(l_current_data);
+                       return OPJ_FALSE;
+               }
 
                l_current_handler = opj_jp2_find_handler(box.type);
                l_current_data_size = box.length - l_nb_bytes_read;
 
                if (l_current_handler != 00) {
+                       if ((OPJ_OFF_T)l_current_data_size > opj_stream_get_number_byte_left(stream)) {
+                               /* do not even try to malloc if we can't read */
+                               opj_event_msg(p_manager, EVT_ERROR, "Invalid box size %d for box '%c%c%c%c'. Need %d bytes, %d bytes remaining \n", box.length, (OPJ_BYTE)(box.type>>24), (OPJ_BYTE)(box.type>>16), (OPJ_BYTE)(box.type>>8), (OPJ_BYTE)(box.type>>0), l_current_data_size, (OPJ_UINT32)opj_stream_get_number_byte_left(stream));
+                               opj_free(l_current_data);
+                               return OPJ_FALSE;
+                       }
                        if (l_current_data_size > l_last_data_size) {
                                OPJ_BYTE* new_current_data = (OPJ_BYTE*)opj_realloc(l_current_data,l_current_data_size);
-                               if (!l_current_data){
+                               if (!new_current_data) {
                                        opj_free(l_current_data);
                     opj_event_msg(p_manager, EVT_ERROR, "Not enough memory to handle jpeg2000 box\n");
                                        return OPJ_FALSE;
@@ -1682,7 +2053,7 @@ OPJ_BOOL opj_jp2_read_header_procedure(  opj_jp2_t *jp2,
                                l_last_data_size = l_current_data_size;
                        }
 
-                       l_nb_bytes_read = opj_stream_read_data(stream,l_current_data,l_current_data_size,p_manager);
+                       l_nb_bytes_read = (OPJ_UINT32)opj_stream_read_data(stream,l_current_data,l_current_data_size,p_manager);
                        if (l_nb_bytes_read != l_current_data_size) {
                                opj_event_msg(p_manager, EVT_ERROR, "Problem with reading JPEG2000 box, stream error\n");
                 opj_free(l_current_data);                
@@ -1909,12 +2280,11 @@ static OPJ_BOOL opj_jp2_read_ftyp(      opj_jp2_t *jp2,
        /* div by 4 */
        jp2->numcl = l_remaining_bytes >> 2;
        if (jp2->numcl) {
-               jp2->cl = (OPJ_UINT32 *) opj_malloc(jp2->numcl * sizeof(OPJ_UINT32));
+               jp2->cl = (OPJ_UINT32 *) opj_calloc(jp2->numcl, sizeof(OPJ_UINT32));
                if (jp2->cl == 00) {
                        opj_event_msg(p_manager, EVT_ERROR, "Not enough memory with FTYP Box\n");
                        return OPJ_FALSE;
                }
-               memset(jp2->cl,0,jp2->numcl * sizeof(OPJ_UINT32));
        }
 
        for (i = 0; i < jp2->numcl; ++i)
@@ -1983,6 +2353,7 @@ static OPJ_BOOL opj_jp2_read_jp2h(  opj_jp2_t *jp2,
        OPJ_UINT32 l_box_size=0, l_current_data_size = 0;
        opj_jp2_box_t box;
        const opj_jp2_header_handler_t * l_current_handler;
+       OPJ_BOOL l_has_ihdr = 0;
 
        /* preconditions */
        assert(p_header_data != 00);
@@ -2023,10 +2394,19 @@ static OPJ_BOOL opj_jp2_read_jp2h(  opj_jp2_t *jp2,
                        jp2->jp2_img_state |= JP2_IMG_STATE_UNKNOWN;
                }
 
+               if (box.type == JP2_IHDR) {
+                       l_has_ihdr = 1;
+               }
+
                p_header_data += l_current_data_size;
                p_header_size -= box.length;
        }
 
+       if (l_has_ihdr == 0) {
+               opj_event_msg(p_manager, EVT_ERROR, "Stream error while reading JP2 Header box: no 'ihdr' box.\n");
+               return OPJ_FALSE;
+       }
+
        jp2->jp2_state |= JP2_STATE_HEADER;
 
        return OPJ_TRUE;
@@ -2055,11 +2435,11 @@ OPJ_BOOL opj_jp2_read_boxhdr_char(   opj_jp2_box_t *box,
        /* process read data */
        opj_read_bytes(p_data, &l_value, 4);
        p_data += 4;
-       box->length = (OPJ_INT32)(l_value);
+       box->length = (OPJ_UINT32)(l_value);
 
        opj_read_bytes(p_data, &l_value, 4);
        p_data += 4;
-       box->type = (OPJ_INT32)(l_value);
+       box->type = (OPJ_UINT32)(l_value);
 
        *p_number_bytes_read = 8;
 
@@ -2084,7 +2464,7 @@ OPJ_BOOL opj_jp2_read_boxhdr_char(   opj_jp2_box_t *box,
 
                opj_read_bytes(p_data, &l_value, 4);
                *p_number_bytes_read += 4;
-               box->length = (OPJ_INT32)(l_value);
+               box->length = (OPJ_UINT32)(l_value);
 
                if (box->length == 0) {
                        opj_event_msg(p_manager, EVT_ERROR, "Cannot handle box of undefined sizes\n");
@@ -2095,7 +2475,10 @@ OPJ_BOOL opj_jp2_read_boxhdr_char(   opj_jp2_box_t *box,
                opj_event_msg(p_manager, EVT_ERROR, "Cannot handle box of undefined sizes\n");
                return OPJ_FALSE;
        }
-
+       if (box->length < *p_number_bytes_read) {
+               opj_event_msg(p_manager, EVT_ERROR, "Box length is inconsistent.\n");
+               return OPJ_FALSE;
+       }
        return OPJ_TRUE;
 }
 
@@ -2315,6 +2698,10 @@ OPJ_BOOL opj_jp2_get_tile(       opj_jp2_t *p_jp2,
                return OPJ_FALSE;
        }
 
+       if (!opj_jp2_check_color(p_image, &(p_jp2->color), p_manager)) {
+               return OPJ_FALSE;
+       }
+
        /* Set Image Color Space */
        if (p_jp2->enumcs == 16)
                p_image->color_space = OPJ_CLRSPC_SRGB;
@@ -2325,11 +2712,6 @@ OPJ_BOOL opj_jp2_get_tile(       opj_jp2_t *p_jp2,
        else
                p_image->color_space = OPJ_CLRSPC_UNKNOWN;
 
-       /* Apply the color space if needed */
-       if(p_jp2->color.jp2_cdef) {
-               opj_jp2_apply_cdef(p_image, &(p_jp2->color));
-       }
-
        if(p_jp2->color.jp2_pclr) {
                /* Part 1, I.5.3.4: Either both or none : */
                if( !p_jp2->color.jp2_pclr->cmap)
@@ -2337,6 +2719,11 @@ OPJ_BOOL opj_jp2_get_tile(       opj_jp2_t *p_jp2,
                else
                        opj_jp2_apply_pclr(p_image, &(p_jp2->color));
        }
+       
+       /* Apply the color space if needed */
+       if(p_jp2->color.jp2_cdef) {
+               opj_jp2_apply_cdef(p_image, &(p_jp2->color));
+       }
 
        if(p_jp2->color.icc_profile_buf) {
                p_image->icc_profile_buf = p_jp2->color.icc_profile_buf;
@@ -2353,9 +2740,8 @@ OPJ_BOOL opj_jp2_get_tile(        opj_jp2_t *p_jp2,
 
 opj_jp2_t* opj_jp2_create(OPJ_BOOL p_is_decoder)
 {
-       opj_jp2_t *jp2 = (opj_jp2_t*)opj_malloc(sizeof(opj_jp2_t));
+       opj_jp2_t *jp2 = (opj_jp2_t*)opj_calloc(1,sizeof(opj_jp2_t));
        if (jp2) {
-               memset(jp2,0,sizeof(opj_jp2_t));
 
                /* create the J2K codec */
                if (! p_is_decoder) {
@@ -2542,6 +2928,7 @@ static OPJ_BOOL opj_jpip_write_cidx(opj_jp2_t *jp2,
   return OPJ_TRUE;
 }
 
+#if 0
 static void write_prxy( int offset_jp2c, int length_jp2c, int offset_idx, int length_idx, opj_stream_private_t *cio,
   opj_event_mgr_t * p_manager )
 {
@@ -2574,8 +2961,10 @@ static void write_prxy( int offset_jp2c, int length_jp2c, int offset_idx, int le
   opj_stream_write_data(cio,l_data_header,4,p_manager);
   opj_stream_seek(cio, lenp+len,p_manager);
 }
+#endif
 
 
+#if 0
 static int write_fidx( int offset_jp2c, int length_jp2c, int offset_idx, int length_idx, opj_stream_private_t *cio,
   opj_event_mgr_t * p_manager )
 {
@@ -2597,4 +2986,5 @@ static int write_fidx( int offset_jp2c, int length_jp2c, int offset_idx, int len
 
   return len;
 }
+#endif
 #endif /* USE_JPIP */