|
|
240d3a |
diff --git a/src/webpimage.cpp b/src/webpimage.cpp
|
|
|
240d3a |
index e4057d6..f1dd77c 100644
|
|
|
240d3a |
--- a/src/webpimage.cpp
|
|
|
240d3a |
+++ b/src/webpimage.cpp
|
|
|
240d3a |
@@ -44,6 +44,8 @@
|
|
|
240d3a |
#include "tiffimage.hpp"
|
|
|
240d3a |
#include "tiffimage_int.hpp"
|
|
|
240d3a |
#include "convert.hpp"
|
|
|
240d3a |
+#include "enforce.hpp"
|
|
|
240d3a |
+
|
|
|
240d3a |
#include <cmath>
|
|
|
240d3a |
#include <iomanip>
|
|
|
240d3a |
#include <string>
|
|
|
240d3a |
@@ -516,6 +518,8 @@ namespace Exiv2 {
|
|
|
240d3a |
DataBuf payload(size);
|
|
|
240d3a |
|
|
|
240d3a |
if (equalsWebPTag(chunkId, WEBP_CHUNK_HEADER_VP8X) && !has_canvas_data) {
|
|
|
240d3a |
+ enforce(size >= 10, Exiv2::kerCorruptedMetadata);
|
|
|
240d3a |
+
|
|
|
240d3a |
has_canvas_data = true;
|
|
|
240d3a |
byte size_buf[WEBP_TAG_SIZE];
|
|
|
240d3a |
|
|
|
240d3a |
@@ -531,6 +535,8 @@ namespace Exiv2 {
|
|
|
240d3a |
size_buf[3] = 0;
|
|
|
240d3a |
pixelHeight_ = Exiv2::getULong(size_buf, littleEndian) + 1;
|
|
|
240d3a |
} else if (equalsWebPTag(chunkId, WEBP_CHUNK_HEADER_VP8) && !has_canvas_data) {
|
|
|
240d3a |
+ enforce(size >= 10, Exiv2::kerCorruptedMetadata);
|
|
|
240d3a |
+
|
|
|
240d3a |
has_canvas_data = true;
|
|
|
240d3a |
io_->read(payload.pData_, payload.size_);
|
|
|
240d3a |
byte size_buf[WEBP_TAG_SIZE];
|
|
|
240d3a |
@@ -547,6 +553,8 @@ namespace Exiv2 {
|
|
|
240d3a |
size_buf[3] = 0;
|
|
|
240d3a |
pixelHeight_ = Exiv2::getULong(size_buf, littleEndian) & 0x3fff;
|
|
|
240d3a |
} else if (equalsWebPTag(chunkId, WEBP_CHUNK_HEADER_VP8L) && !has_canvas_data) {
|
|
|
240d3a |
+ enforce(size >= 5, Exiv2::kerCorruptedMetadata);
|
|
|
240d3a |
+
|
|
|
240d3a |
has_canvas_data = true;
|
|
|
240d3a |
byte size_buf_w[2];
|
|
|
240d3a |
byte size_buf_h[3];
|
|
|
240d3a |
@@ -564,6 +572,8 @@ namespace Exiv2 {
|
|
|
240d3a |
size_buf_h[1] = ((size_buf_h[1] >> 6) & 0x3) | ((size_buf_h[2] & 0xF) << 0x2);
|
|
|
240d3a |
pixelHeight_ = Exiv2::getUShort(size_buf_h, littleEndian) + 1;
|
|
|
240d3a |
} else if (equalsWebPTag(chunkId, WEBP_CHUNK_HEADER_ANMF) && !has_canvas_data) {
|
|
|
240d3a |
+ enforce(size >= 12, Exiv2::kerCorruptedMetadata);
|
|
|
240d3a |
+
|
|
|
240d3a |
has_canvas_data = true;
|
|
|
240d3a |
byte size_buf[WEBP_TAG_SIZE];
|
|
|
240d3a |
|