| Index: media/filters/jpeg_parser.cc
|
| diff --git a/media/filters/jpeg_parser.cc b/media/filters/jpeg_parser.cc
|
| index bb07bd710aa54f8d6444e4c9af31fd7dad320f59..3ab9168a25065d04fbb4daf97622a67fd4cf5cc1 100644
|
| --- a/media/filters/jpeg_parser.cc
|
| +++ b/media/filters/jpeg_parser.cc
|
| @@ -269,6 +269,65 @@ static bool ParseSOS(const char* buffer,
|
| return true;
|
| }
|
|
|
| +// |eoi_ptr| will point to the end of image (after EOI marker) after search
|
| +// succeeds. Returns true on EOI marker found, or false.
|
| +static bool SearchEOI(const char* buffer, size_t length, const char** eoi_ptr) {
|
| + DCHECK(buffer);
|
| + DCHECK(eoi_ptr);
|
| + BigEndianReader reader(buffer, length);
|
| + uint8_t marker1;
|
| + uint8_t marker2;
|
| +
|
| + while (reader.remaining() > 0) {
|
| + READ_U8_OR_RETURN_FALSE(&marker1);
|
| + if (marker1 != JPEG_MARKER_PREFIX)
|
| + continue;
|
| +
|
| + do {
|
| + READ_U8_OR_RETURN_FALSE(&marker2);
|
| + } while (marker2 == JPEG_MARKER_PREFIX); // skip fill bytes
|
| +
|
| + switch (marker2) {
|
| + // Compressed data escape.
|
| + case 0x00:
|
| + break;
|
| + // Restart
|
| + case JPEG_RST0:
|
| + case JPEG_RST1:
|
| + case JPEG_RST2:
|
| + case JPEG_RST3:
|
| + case JPEG_RST4:
|
| + case JPEG_RST5:
|
| + case JPEG_RST6:
|
| + case JPEG_RST7:
|
| + break;
|
| + case JPEG_EOI:
|
| + *eoi_ptr = reader.ptr();
|
| + return true;
|
| + default:
|
| + // Skip for other markers.
|
| + uint16_t size;
|
| + READ_U16_OR_RETURN_FALSE(&size);
|
| + if (size < sizeof(size)) {
|
| + DLOG(ERROR) << "Ill-formed JPEG. Segment size (" << size
|
| + << ") is smaller than size field (" << sizeof(size)
|
| + << ")";
|
| + return false;
|
| + }
|
| + size -= sizeof(size);
|
| +
|
| + if (!reader.Skip(size)) {
|
| + DLOG(ERROR) << "Ill-formed JPEG. Remaining size ("
|
| + << reader.remaining()
|
| + << ") is smaller than header specified (" << size << ")";
|
| + return false;
|
| + }
|
| + break;
|
| + }
|
| + }
|
| + return false;
|
| +}
|
| +
|
| // |result| is already initialized to 0 in ParseJpegPicture.
|
| static bool ParseSOI(const char* buffer,
|
| size_t length,
|
| @@ -371,7 +430,14 @@ static bool ParseSOI(const char* buffer,
|
|
|
| // Scan data follows scan header immediately.
|
| result->data = reader.ptr();
|
| - result->data_size = reader.remaining();
|
| + const char* eoi_ptr = nullptr;
|
| + if (!SearchEOI(reader.ptr(), reader.remaining(), &eoi_ptr)) {
|
| + DLOG(ERROR) << "SearchEOI failed";
|
| + return false;
|
| + }
|
| + result->data_size = eoi_ptr - result->data;
|
| + const int kSoiSize = 2;
|
| + result->image_size = eoi_ptr - buffer + kSoiSize;
|
|
|
| return true;
|
| }
|
|
|