[poppler] Branch 'poppler-0.10' - poppler/GfxState.cc

Albert Astals Cid aacid at kemper.freedesktop.org
Wed Nov 5 13:49:37 PST 2008


 poppler/GfxState.cc |    7 ++++---
 1 file changed, 4 insertions(+), 3 deletions(-)

New commits:
commit 467b83c668281f8d100cba06eea01901c9f875e0
Author: Albert Astals Cid <aacid at kde.org>
Date:   Wed Nov 5 22:47:30 2008 +0100

    Do not abort if indexHighA is 'invalid', move it to the closest valid value and try with it
    
    For the bug 18374 it works and does not seem a security problem

diff --git a/poppler/GfxState.cc b/poppler/GfxState.cc
index 2e01b2b..7bb0667 100644
--- a/poppler/GfxState.cc
+++ b/poppler/GfxState.cc
@@ -1122,9 +1122,10 @@ GfxColorSpace *GfxIndexedColorSpace::parse(Array *arr) {
     // values larger than 255 creates a security hole: if nComps *
     // indexHigh is greater than 2^31, the loop below may overwrite
     // past the end of the array
-    error(-1, "Bad Indexed color space (invalid indexHigh value)");
-    delete baseA;
-    goto err2;
+    int previousValue = indexHighA;
+    if (indexHighA < 0) indexHighA = 0;
+    else indexHighA = 255;
+    error(-1, "Bad Indexed color space (invalid indexHigh value, was %d using %d to try to recover)", previousValue, indexHighA);
   }
   obj1.free();
   cs = new GfxIndexedColorSpace(baseA, indexHighA);


More information about the poppler mailing list