Blame SOURCES/jasper-2.0.14-CVE-2016-9396.patch

491fbb
diff -urNp old/src/libjasper/jpc/jpc_cs.c new/src/libjasper/jpc/jpc_cs.c
491fbb
--- old/src/libjasper/jpc/jpc_cs.c	2018-05-30 09:01:54.160406645 +0200
491fbb
+++ new/src/libjasper/jpc/jpc_cs.c	2018-05-30 09:05:24.527094308 +0200
491fbb
@@ -795,6 +795,9 @@ static int jpc_cox_getcompparms(jpc_ms_t
491fbb
 	if (compparms->numdlvls > 32) {
491fbb
 		goto error;
491fbb
 	}
491fbb
+	if (compparms->qmfbid != JPC_COX_INS &&
491fbb
+	    compparms->qmfbid != JPC_COX_RFT)
491fbb
+		goto error;
491fbb
 	compparms->numrlvls = compparms->numdlvls + 1;
491fbb
 	if (compparms->numrlvls > JPC_MAXRLVLS) {
491fbb
 		goto error;