DescriptionMerge 132961 (merge bug: http://crbug.com/158840) - Fix potential overflow in jpeg exif reader. Found by aedla@google.com.
https://bugs.webkit.org/show_bug.cgi?id=100320
Reviewed by Eric Seidel.
Adding more than 1 element past an array is undefined, so don't do it.
No test, since in practice ifd will just overflow and `end - ifd` will
become much larget than 2 and the `if (end - ifd < 2)` a few lines
down will catch that case.
* platform/image-decoders/jpeg/JPEGImageDecoder.cpp:
(WebCore::readImageOrientation):
TBR=thakis@chromium.org
Committed: https://src.chromium.org/viewvc/chrome?view=rev&revision=133086
Patch Set 1 #
Messages
Total messages: 1 (0 generated)
|