From bd88611ed9ad7144ec4f3de54790cd848175891b Mon Sep 17 00:00:00 2001 From: Young_X Date: Fri, 23 Nov 2018 17:15:05 +0800 Subject: [PATCH] [JP3D] To avoid divisions by zero / undefined behaviour on shift (CVE-2018-14423 Signed-off-by: Young_X --- src/lib/openjp3d/pi.c | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/src/lib/openjp3d/pi.c b/src/lib/openjp3d/pi.c index a03be45e..a58ebcc7 100644 --- a/src/lib/openjp3d/pi.c +++ b/src/lib/openjp3d/pi.c @@ -223,6 +223,14 @@ static bool pi_next_rpcl(opj_pi_iterator_t * pi) rpx = res->pdx + levelnox; rpy = res->pdy + levelnoy; rpz = res->pdz + levelnoz; + + /* To avoid divisions by zero / undefined behaviour on shift */ + if (rpx >= 31 || ((comp->dx << rpx) >> rpx) != comp->dx || + rpy >= 31 || ((comp->dy << rpy) >> rpy) != comp->dy || + rpz >= 31 || ((comp->dz << rpz) >> rpz) != comp->dz) { + continue; + } + if ((!(pi->x % (comp->dx << rpx) == 0) || (pi->x == pi->tx0 && (trx0 << levelnox) % (1 << rpx)))) { continue; @@ -329,6 +337,14 @@ static bool pi_next_pcrl(opj_pi_iterator_t * pi) rpx = res->pdx + levelnox; rpy = res->pdy + levelnoy; rpz = res->pdz + levelnoz; + + /* To avoid divisions by zero / undefined behaviour on shift */ + if (rpx >= 31 || ((comp->dx << rpx) >> rpx) != comp->dx || + rpy >= 31 || ((comp->dy << rpy) >> rpy) != comp->dy || + rpz >= 31 || ((comp->dz << rpz) >> rpz) != comp->dz) { + continue; + } + if ((!(pi->x % (comp->dx << rpx) == 0) || (pi->x == pi->tx0 && (trx0 << levelnox) % (1 << rpx)))) { continue; @@ -432,6 +448,14 @@ static bool pi_next_cprl(opj_pi_iterator_t * pi) rpx = res->pdx + levelnox; rpy = res->pdy + levelnoy; rpz = res->pdz + levelnoz; + + /* To avoid divisions by zero / undefined behaviour on shift */ + if (rpx >= 31 || ((comp->dx << rpx) >> rpx) != comp->dx || + rpy >= 31 || ((comp->dy << rpy) >> rpy) != comp->dy || + rpz >= 31 || ((comp->dz << rpz) >> rpz) != comp->dz) { + continue; + } + if ((!(pi->x % (comp->dx << rpx) == 0) || (pi->x == pi->tx0 && (trx0 << levelnox) % (1 << rpx)))) { continue; -- 2.30.2