9ad3263e80
- Security fixes Multiple integer overflows Buffer overflow in the jas_stream_printf execute arbitrary code on decodes images Security: CVE-2008-3520 Security: CVE-2008-3522 Security: CVE-2011-4516 Security: CVE-2011-4517 PR: 163718 Obtained from: Fedora Feature safe: yes
11 lines
497 B
C
11 lines
497 B
C
--- src/libjasper/jpc/jpc_t2cod.c.orig 2007-01-19 22:43:07.000000000 +0100
|
|
+++ src/libjasper/jpc/jpc_t2cod.c 2013-04-17 22:32:23.000000000 +0200
|
|
@@ -573,7 +573,7 @@
|
|
}
|
|
if (pchglist->numpchgs >= pchglist->maxpchgs) {
|
|
newmaxpchgs = pchglist->maxpchgs + 128;
|
|
- if (!(newpchgs = jas_realloc(pchglist->pchgs, newmaxpchgs * sizeof(jpc_pchg_t *)))) {
|
|
+ if (!(newpchgs = jas_realloc2(pchglist->pchgs, newmaxpchgs, sizeof(jpc_pchg_t *)))) {
|
|
return -1;
|
|
}
|
|
pchglist->maxpchgs = newmaxpchgs;
|