Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(278)

Issue 2384063006: Fix cmdStageAllocMatrix parameter swap (Closed)

Created:
4 years, 2 months ago by kcwu
Modified:
4 years, 2 months ago
CC:
pdfium-reviews_googlegroups.com
Target Ref:
refs/heads/master
Project:
pdfium
Visibility:
Public.

Description

Fix cmdStageAllocMatrix parameter swap For cmdStageAllocMatrix, InputChans is length of Matrix, OutputChans is length of Offsets. The original code will allocate NewElem->Offset with length Cols=InputChans (cmslut.c:417). This results in heap buffer overflow later. BUG=chromium:651849 Committed: https://pdfium.googlesource.com/pdfium/+/958e57cbe864f356140b74cbc3b70bf352187bd4

Patch Set 1 #

Unified diffs Side-by-side diffs Delta from patch set Stats (+15 lines, -1 line) Patch
A third_party/lcms2-2.6/0009-cmdStageAllocMatrix-param-swap.patch View 1 chunk +13 lines, -0 lines 0 comments Download
M third_party/lcms2-2.6/README.pdfium View 1 chunk +1 line, -0 lines 0 comments Download
M third_party/lcms2-2.6/src/cmstypes.c View 1 chunk +1 line, -1 line 0 comments Download

Messages

Total messages: 10 (4 generated)
kcwu
I found the root cause -- offset buffer allocated with wrong length. However, I am ...
4 years, 2 months ago (2016-10-04 02:22:40 UTC) #2
dsinclair
I don't know if this is right either. Can we send the patch upstream and ...
4 years, 2 months ago (2016-10-04 13:15:14 UTC) #4
kcwu
On 2016/10/04 13:15:14, dsinclair wrote: > I don't know if this is right either. Can ...
4 years, 2 months ago (2016-10-04 14:49:50 UTC) #5
Tom Sepez
lgtm
4 years, 2 months ago (2016-10-04 18:26:38 UTC) #6
commit-bot: I haz the power
CQ is trying da patch. Follow status at https://chromium-cq-status.appspot.com/v2/patch-status/codereview.chromium.org/2384063006/1
4 years, 2 months ago (2016-10-05 01:41:49 UTC) #8
commit-bot: I haz the power
4 years, 2 months ago (2016-10-05 02:00:44 UTC) #10
Message was sent while issue was closed.
Committed patchset #1 (id:1) as
https://pdfium.googlesource.com/pdfium/+/958e57cbe864f356140b74cbc3b70bf35218...

Powered by Google App Engine
This is Rietveld 408576698