DescriptionMerge to M44: Integer overflow in CJBig2_Image::expand
1. New size should be larger than old size in JBig2_Realloc.
2. Arguments are integers but parameters are size_t in JBIG2_memset.
After integer overflows, it will be presented as a huge
unsigned number on 64 bits system.
BUG=483981
R=brucedawson@chromium.org, tsepez@chromium.org
Review URL: https://codereview.chromium.org/1148643002
(cherry picked from commit e9ccc9bc449846107f1c539e25677f4877ddf22f)
Committed: https://pdfium.googlesource.com/pdfium/+/12d0f7b4eae9c2b40433500b15955f61050132aa
Patch Set 1 #
Messages
Total messages: 3 (0 generated)
|