Merge branch 'gnome-updates'
[jackhill/guix/guix.git] / gnu / packages / patches / jasper-CVE-2014-9029.patch
CommitLineData
90bcecc5
LF
1Fix CVE-2014-9029 (Heap overflows in libjasper).
2
3Copied from Fedora.
4
5http://pkgs.fedoraproject.org/cgit/rpms/jasper.git/tree/jasper-CVE-2014-9029.patch
6https://bugzilla.redhat.com/show_bug.cgi?id=1167537
7
8--- jasper-1.900.1.orig/src/libjasper/jpc/jpc_dec.c 2014-11-27 12:45:44.000000000 +0100
9+++ jasper-1.900.1/src/libjasper/jpc/jpc_dec.c 2014-11-27 12:44:58.000000000 +0100
10@@ -1281,7 +1281,7 @@ static int jpc_dec_process_coc(jpc_dec_t
11 jpc_coc_t *coc = &ms->parms.coc;
12 jpc_dec_tile_t *tile;
13
14- if (JAS_CAST(int, coc->compno) > dec->numcomps) {
15+ if (JAS_CAST(int, coc->compno) >= dec->numcomps) {
16 jas_eprintf("invalid component number in COC marker segment\n");
17 return -1;
18 }
19@@ -1307,7 +1307,7 @@ static int jpc_dec_process_rgn(jpc_dec_t
20 jpc_rgn_t *rgn = &ms->parms.rgn;
21 jpc_dec_tile_t *tile;
22
23- if (JAS_CAST(int, rgn->compno) > dec->numcomps) {
24+ if (JAS_CAST(int, rgn->compno) >= dec->numcomps) {
25 jas_eprintf("invalid component number in RGN marker segment\n");
26 return -1;
27 }
28@@ -1356,7 +1356,7 @@ static int jpc_dec_process_qcc(jpc_dec_t
29 jpc_qcc_t *qcc = &ms->parms.qcc;
30 jpc_dec_tile_t *tile;
31
32- if (JAS_CAST(int, qcc->compno) > dec->numcomps) {
33+ if (JAS_CAST(int, qcc->compno) >= dec->numcomps) {
34 jas_eprintf("invalid component number in QCC marker segment\n");
35 return -1;
36 }