[poppler] poppler/Hints.cc

GitLab Mirror gitlab-mirror at kemper.freedesktop.org
Tue Mar 15 14:25:00 UTC 2022


 poppler/Hints.cc |   24 +++++++++++++++++-------
 1 file changed, 17 insertions(+), 7 deletions(-)

New commits:
commit 81044c64b9ed9a10ae82a28bac753060bdfdac74
Author: Albert Astals Cid <aacid at kde.org>
Date:   Tue Mar 15 15:14:32 2022 +0100

    Hints::readTables: bail out if we run out of file when reading
    
    Fixes #1230

diff --git a/poppler/Hints.cc b/poppler/Hints.cc
index 79f04088..4707e1c6 100644
--- a/poppler/Hints.cc
+++ b/poppler/Hints.cc
@@ -5,7 +5,7 @@
 // This file is licensed under the GPLv2 or later
 //
 // Copyright 2010, 2012, 2013 Hib Eris <hib at hiberis.nl>
-// Copyright 2010, 2011, 2013, 2014, 2016-2019, 2021 Albert Astals Cid <aacid at kde.org>
+// Copyright 2010, 2011, 2013, 2014, 2016-2019, 2021, 2022 Albert Astals Cid <aacid at kde.org>
 // Copyright 2010, 2013 Pino Toscano <pino at kde.org>
 // Copyright 2013 Adrian Johnson <ajohnson at redneon.com>
 // Copyright 2014 Fabio D'Urso <fabiodurso at hotmail.it>
@@ -189,21 +189,31 @@ void Hints::readTables(BaseStream *str, Linearization *linearization, XRef *xref
     char *p = &buf[0];
 
     if (hintsOffset && hintsLength) {
-        Stream *s = str->makeSubStream(hintsOffset, false, hintsLength, Object(objNull));
+        std::unique_ptr<Stream> s(str->makeSubStream(hintsOffset, false, hintsLength, Object(objNull)));
         s->reset();
         for (unsigned int i = 0; i < hintsLength; i++) {
-            *p++ = s->getChar();
+            const int c = s->getChar();
+            if (unlikely(c == EOF)) {
+                error(errSyntaxWarning, -1, "Found EOF while reading hints");
+                ok = false;
+                return;
+            }
+            *p++ = c;
         }
-        delete s;
     }
 
     if (hintsOffset2 && hintsLength2) {
-        Stream *s = str->makeSubStream(hintsOffset2, false, hintsLength2, Object(objNull));
+        std::unique_ptr<Stream> s(str->makeSubStream(hintsOffset2, false, hintsLength2, Object(objNull)));
         s->reset();
         for (unsigned int i = 0; i < hintsLength2; i++) {
-            *p++ = s->getChar();
+            const int c = s->getChar();
+            if (unlikely(c == EOF)) {
+                error(errSyntaxWarning, -1, "Found EOF while reading hints2");
+                ok = false;
+                return;
+            }
+            *p++ = c;
         }
-        delete s;
     }
 
     MemStream *memStream = new MemStream(&buf[0], 0, bufLength, Object(objNull));


More information about the poppler mailing list