Blame SOURCES/ghostscript-cve-2018-19477.patch

a60c09
From 606a22e77e7f081781e99e44644cd0119f559e03 Mon Sep 17 00:00:00 2001
a60c09
From: Ken Sharp <ken.sharp@artifex.com>
a60c09
Date: Wed, 14 Nov 2018 09:27:00 +0000
a60c09
Subject: [PATCH] Bug #700168 - add a type check
a60c09
a60c09
Bug #700168 "Type confusion in JBIG2Decode"
a60c09
a60c09
The code was assuming that .jbig2globalctx was a structure allocated
a60c09
by the graphics library, without checking.
a60c09
a60c09
Add a check to see that it is a structure and that its the correct
a60c09
type of structure.
a60c09
---
a60c09
 psi/zfjbig2.c | 2 ++
a60c09
 1 file changed, 2 insertions(+)
a60c09
a60c09
diff --git a/psi/zfjbig2.c b/psi/zfjbig2.c
a60c09
index a3d13a2..07b470f 100644
a60c09
--- a/psi/zfjbig2.c
a60c09
+++ b/psi/zfjbig2.c
a60c09
@@ -72,6 +72,8 @@ z_jbig2decode(i_ctx_t * i_ctx_p)
a60c09
     if (r_has_type(op, t_dictionary)) {
a60c09
         check_dict_read(*op);
a60c09
         if ( dict_find_string(op, ".jbig2globalctx", &sop) > 0) {
a60c09
+            if (!r_is_struct(sop) || !r_has_stype(sop, imemory, st_jbig2_global_data_t))
a60c09
+                return_error(gs_error_typecheck);
a60c09
             gref = r_ptr(sop, s_jbig2_global_data_t);
a60c09
             s_jbig2decode_set_global_data((stream_state*)&state, gref);
a60c09
         }
a60c09
-- 
a60c09
2.17.2
a60c09