Patrick Williams | c0f7c04 | 2017-02-23 20:41:17 -0600 | [diff] [blame] | 1 | From d9783e4a1476b6787a51c5ae9e9b3156527589f0 Mon Sep 17 00:00:00 2001 |
| 2 | From: erouault <erouault> |
| 3 | Date: Mon, 11 Jul 2016 21:26:03 +0000 |
| 4 | Subject: [PATCH 1/2] * tools/tiffcrop.c: Avoid access outside of stack |
| 5 | allocated array on a tiled separate TIFF with more than 8 samples per pixel. |
| 6 | Reported by Kaixiang Zhang of the Cloud Security Team, Qihoo 360 |
| 7 | (CVE-2016-5321, bugzilla #2558) |
| 8 | |
| 9 | CVE: CVE-2016-5321 |
| 10 | Upstream-Status: Backport |
| 11 | https://github.com/vadz/libtiff/commit/d9783e4a1476b6787a51c5ae9e9b3156527589f0 |
| 12 | |
| 13 | Signed-off-by: Yi Zhao <yi.zhao@windirver.com> |
| 14 | --- |
| 15 | ChangeLog | 7 +++++++ |
| 16 | tools/tiffcrop.c | 2 +- |
| 17 | 2 files changed, 8 insertions(+), 1 deletion(-) |
| 18 | |
| 19 | diff --git a/ChangeLog b/ChangeLog |
| 20 | index e98d54d..4e0302f 100644 |
| 21 | --- a/ChangeLog |
| 22 | +++ b/ChangeLog |
| 23 | @@ -1,3 +1,10 @@ |
| 24 | +2016-07-11 Even Rouault <even.rouault at spatialys.com> |
| 25 | + |
| 26 | + * tools/tiffcrop.c: Avoid access outside of stack allocated array |
| 27 | + on a tiled separate TIFF with more than 8 samples per pixel. |
| 28 | + Reported by Kaixiang Zhang of the Cloud Security Team, Qihoo 360 |
| 29 | + (CVE-2016-5321, bugzilla #2558) |
| 30 | + |
| 31 | 2015-12-27 Even Rouault <even.rouault at spatialys.com> |
| 32 | |
| 33 | * libtiff/tif_next.c: fix potential out-of-bound write in NeXTDecode() |
| 34 | diff --git a/tools/tiffcrop.c b/tools/tiffcrop.c |
| 35 | index d959ae3..6fc8fc1 100644 |
| 36 | --- a/tools/tiffcrop.c |
| 37 | +++ b/tools/tiffcrop.c |
| 38 | @@ -989,7 +989,7 @@ static int readSeparateTilesIntoBuffer (TIFF* in, uint8 *obuf, |
| 39 | nrow = (row + tl > imagelength) ? imagelength - row : tl; |
| 40 | for (col = 0; col < imagewidth; col += tw) |
| 41 | { |
| 42 | - for (s = 0; s < spp; s++) |
| 43 | + for (s = 0; s < spp && s < MAX_SAMPLES; s++) |
| 44 | { /* Read each plane of a tile set into srcbuffs[s] */ |
| 45 | tbytes = TIFFReadTile(in, srcbuffs[s], col, row, 0, s); |
| 46 | if (tbytes < 0 && !ignore) |
| 47 | -- |
| 48 | 2.7.4 |
| 49 | |