app-text/poppler: Fix CVE-2017-14617
authorAndreas Sturmlechner <asturm@gentoo.org>
Fri, 24 Nov 2017 21:31:04 +0000 (22:31 +0100)
committerAndreas Sturmlechner <asturm@gentoo.org>
Fri, 24 Nov 2017 23:06:22 +0000 (00:06 +0100)
Bug: https://bugs.gentoo.org/631596
Package-Manager: Portage-2.3.16, Repoman-2.3.6

app-text/poppler/files/poppler-0.57.0-CVE-2017-14617.patch [new file with mode: 0644]
app-text/poppler/poppler-0.57.0-r1.ebuild

diff --git a/app-text/poppler/files/poppler-0.57.0-CVE-2017-14617.patch b/app-text/poppler/files/poppler-0.57.0-CVE-2017-14617.patch
new file mode 100644 (file)
index 0000000..2794795
--- /dev/null
@@ -0,0 +1,31 @@
+From 939465c40902d72e0c05d4f3a27ee67e4a007ed7 Mon Sep 17 00:00:00 2001
+From: Albert Astals Cid <aacid@kde.org>
+Date: Tue, 19 Sep 2017 21:19:03 +0200
+Subject: [PATCH] Fix crash in broken files
+
+Bug #102854
+---
+ poppler/Stream.cc | 5 ++---
+ 1 file changed, 2 insertions(+), 3 deletions(-)
+
+diff --git a/poppler/Stream.cc b/poppler/Stream.cc
+index f4eda85b..0ad602c7 100644
+--- a/poppler/Stream.cc
++++ b/poppler/Stream.cc
+@@ -454,11 +454,10 @@ ImageStream::ImageStream(Stream *strA, int widthA, int nCompsA, int nBitsA) {
+     } else {
+       imgLineSize = nVals;
+     }
+-    if (width > INT_MAX / nComps) {
+-      // force a call to gmallocn(-1,...), which will throw an exception
++    if (nComps <= 0 || width > INT_MAX / nComps) {
+       imgLineSize = -1;
+     }
+-    imgLine = (Guchar *)gmallocn(imgLineSize, sizeof(Guchar));
++    imgLine = (Guchar *)gmallocn_checkoverflow(imgLineSize, sizeof(Guchar));
+   }
+   imgIdx = nVals;
+ }
+-- 
+2.14.1
+
index a19b815e59553d2e8b1d779368ac0396e8551b33..b7a421f73e2c9e32a99e647d721852de9b342c2e 100644 (file)
@@ -70,6 +70,7 @@ PATCHES=(
        "${FILESDIR}/${P}-CVE-2017-14518.patch"
        "${FILESDIR}/${P}-CVE-2017-14519.patch"
        "${FILESDIR}/${P}-CVE-2017-14520.patch"
+       "${FILESDIR}/${P}-CVE-2017-14617.patch"
        "${FILESDIR}/${P}-CVE-2017-14926.patch"
        "${FILESDIR}/${P}-CVE-2017-14927.patch"
        "${FILESDIR}/${P}-CVE-2017-14928.patch"