Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(266)

Unified Diff: third_party/lcms2-2.6/0003-uninit.patch

Issue 2362813002: Fix use uninitialized value and stack buffer overflow read (Closed)
Patch Set: Created 4 years, 3 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
« no previous file with comments | « no previous file | third_party/lcms2-2.6/README.pdfium » ('j') | third_party/lcms2-2.6/src/cmstypes.c » ('J')
Expand Comments ('e') | Collapse Comments ('c') | Show Comments Hide Comments ('s')
Index: third_party/lcms2-2.6/0003-uninit.patch
diff --git a/third_party/lcms2-2.6/0003-uninit.patch b/third_party/lcms2-2.6/0003-uninit.patch
new file mode 100644
index 0000000000000000000000000000000000000000..50103dc4f6560c03ced529f9736dfbbaf4c8060f
--- /dev/null
+++ b/third_party/lcms2-2.6/0003-uninit.patch
@@ -0,0 +1,21 @@
+diff --git a/third_party/lcms2-2.6/src/cmstypes.c b/third_party/lcms2-2.6/src/cmstypes.c
+index 9fe5e2a..feba387 100644
+--- a/third_party/lcms2-2.6/src/cmstypes.c
++++ b/third_party/lcms2-2.6/src/cmstypes.c
+@@ -2985,7 +2985,7 @@ void *Type_ColorantTable_Read(struct _cms_typehandler_struct* self, cmsIOHANDLER
+ for (i=0; i < Count; i++) {
+
+ if (io ->Read(io, Name, 32, 1) != 1) goto Error;
+- Name[33] = 0;
++ Name[32] = 0;
+
+ if (!_cmsReadUInt16Array(io, 3, PCS)) goto Error;
+
+@@ -3112,6 +3112,7 @@ void *Type_NamedColor_Read(struct _cms_typehandler_struct* self, cmsIOHANDLER* i
+
+ memset(Colorant, 0, sizeof(Colorant));
+ if (io -> Read(io, Root, 32, 1) != 1) return NULL;
++ Root[32] = 0;
+ if (!_cmsReadUInt16Array(io, 3, PCS)) goto Error;
+ if (!_cmsReadUInt16Array(io, nDeviceCoords, Colorant)) goto Error;
+
« no previous file with comments | « no previous file | third_party/lcms2-2.6/README.pdfium » ('j') | third_party/lcms2-2.6/src/cmstypes.c » ('J')

Powered by Google App Engine
This is Rietveld 408576698