425a81
Backport of upstream commit:
425a81
425a81
From 411a4068f8c464e883358bf403a3e25158863823 Mon Sep 17 00:00:00 2001
425a81
From: Michael Adams <mdadams@ece.uvic.ca>
425a81
Date: Mon, 24 Oct 2016 06:56:08 -0700
425a81
Subject: [PATCH] Fixed a few bugs in the RAS encoder and decoder where errors
425a81
 were tested with assertions instead of being gracefully handled.
425a81
425a81
diff -pruN jasper-1.900.1.orig/src/libjasper/ras/ras_dec.c jasper-1.900.1/src/libjasper/ras/ras_dec.c
425a81
--- jasper-1.900.1.orig/src/libjasper/ras/ras_dec.c	2007-01-19 22:43:04.000000000 +0100
425a81
+++ jasper-1.900.1/src/libjasper/ras/ras_dec.c	2017-03-31 22:38:04.000000000 +0200
425a81
@@ -257,9 +257,16 @@ static int ras_getdatastd(jas_stream_t *
425a81
 	/* Avoid compiler warnings about unused parameters. */
425a81
 	cmap = 0;
425a81
 
425a81
+	assert(jas_image_numcmpts(image) <= 3);
425a81
+
425a81
+	for (i = 0; i < 3; ++i) {
425a81
+		data[i] = 0;
425a81
+	}
425a81
+
425a81
 	for (i = 0; i < jas_image_numcmpts(image); ++i) {
425a81
-		data[i] = jas_matrix_create(1, jas_image_width(image));
425a81
-		assert(data[i]);
425a81
+		if (!(data[i] = jas_matrix_create(1, jas_image_width(image)))) {
425a81
+			goto error;
425a81
+		}
425a81
 	}
425a81
 
425a81
 	pad = RAS_ROWSIZE(hdr) - (hdr->width * hdr->depth + 7) / 8;
425a81
@@ -270,7 +277,7 @@ static int ras_getdatastd(jas_stream_t *
425a81
 		for (x = 0; x < hdr->width; x++) {
425a81
 			while (nz < hdr->depth) {
425a81
 				if ((c = jas_stream_getc(in)) == EOF) {
425a81
-					return -1;
425a81
+					goto error;
425a81
 				}
425a81
 				z = (z << 8) | c;
425a81
 				nz += 8;
425a81
@@ -290,22 +297,31 @@ static int ras_getdatastd(jas_stream_t *
425a81
 		}
425a81
 		if (pad) {
425a81
 			if ((c = jas_stream_getc(in)) == EOF) {
425a81
-				return -1;
425a81
+				goto error;
425a81
 			}
425a81
 		}
425a81
 		for (i = 0; i < jas_image_numcmpts(image); ++i) {
425a81
 			if (jas_image_writecmpt(image, i, 0, y, hdr->width, 1,
425a81
 			  data[i])) {
425a81
-				return -1;
425a81
+				goto error;
425a81
 			}
425a81
 		}
425a81
 	}
425a81
 
425a81
 	for (i = 0; i < jas_image_numcmpts(image); ++i) {
425a81
 		jas_matrix_destroy(data[i]);
425a81
+		data[i] = 0;
425a81
 	}
425a81
 
425a81
 	return 0;
425a81
+
425a81
+error:
425a81
+	for (i = 0; i < 3; ++i) {
425a81
+		if (data[i]) {
425a81
+			jas_matrix_destroy(data[i]);
425a81
+		}
425a81
+	}
425a81
+	return -1;
425a81
 }
425a81
 
425a81
 static int ras_getcmap(jas_stream_t *in, ras_hdr_t *hdr, ras_cmap_t *cmap)
425a81
@@ -324,7 +340,9 @@ static int ras_getcmap(jas_stream_t *in,
425a81
 		{
425a81
 		jas_eprintf("warning: palettized images not fully supported\n");
425a81
 		numcolors = 1 << hdr->depth;
425a81
-		assert(numcolors <= RAS_CMAP_MAXSIZ);
425a81
+		if (numcolors > RAS_CMAP_MAXSIZ) {
425a81
+			return -1;
425a81
+		}
425a81
 		actualnumcolors = hdr->maplength / 3;
425a81
 		for (i = 0; i < numcolors; i++) {
425a81
 			cmap->data[i] = 0;
425a81
diff -pruN jasper-1.900.1.orig/src/libjasper/ras/ras_enc.c jasper-1.900.1/src/libjasper/ras/ras_enc.c
425a81
--- jasper-1.900.1.orig/src/libjasper/ras/ras_enc.c	2017-03-31 22:20:38.000000000 +0200
425a81
+++ jasper-1.900.1/src/libjasper/ras/ras_enc.c	2017-03-31 22:38:04.000000000 +0200
425a81
@@ -230,9 +230,17 @@ static int ras_putdatastd(jas_stream_t *
425a81
 	jas_matrix_t *data[3];
425a81
 	int i;
425a81
 
425a81
+	assert(numcmpts <= 3);
425a81
+
425a81
+	for (i = 0; i < 3; ++i) {
425a81
+		data[i] = 0;
425a81
+	}
425a81
+
425a81
 	for (i = 0; i < numcmpts; ++i) {
425a81
-		data[i] = jas_matrix_create(jas_image_height(image), jas_image_width(image));
425a81
-		assert(data[i]);
425a81
+		if (!(data[i] = jas_matrix_create(jas_image_height(image),
425a81
+		  jas_image_width(image)))) {
425a81
+			goto error;
425a81
+		}
425a81
 	}
425a81
 
425a81
 	rowsize = RAS_ROWSIZE(hdr);
425a81
@@ -244,7 +252,7 @@ static int ras_putdatastd(jas_stream_t *
425a81
 		for (i = 0; i < numcmpts; ++i) {
425a81
 			if (jas_image_readcmpt(image, cmpts[i], 0, y,
425a81
 					jas_image_width(image), 1, data[i])) {
425a81
-				return -1;
425a81
+				goto error;
425a81
 			}
425a81
 		}
425a81
 		z = 0;
425a81
@@ -263,7 +271,7 @@ static int ras_putdatastd(jas_stream_t *
425a81
 			while (nz >= 8) {
425a81
 				c = (z >> (nz - 8)) & 0xff;
425a81
 				if (jas_stream_putc(out, c) == EOF) {
425a81
-					return -1;
425a81
+					goto error;
425a81
 				}
425a81
 				nz -= 8;
425a81
 				z &= RAS_ONES(nz);
425a81
@@ -272,21 +280,30 @@ static int ras_putdatastd(jas_stream_t *
425a81
 		if (nz > 0) {
425a81
 			c = (z >> (8 - nz)) & RAS_ONES(nz);
425a81
 			if (jas_stream_putc(out, c) == EOF) {
425a81
-				return -1;
425a81
+				goto error;
425a81
 			}
425a81
 		}
425a81
 		if (pad % 2) {
425a81
 			if (jas_stream_putc(out, 0) == EOF) {
425a81
-				return -1;
425a81
+				goto error;
425a81
 			}
425a81
 		}
425a81
 	}
425a81
 
425a81
 	for (i = 0; i < numcmpts; ++i) {
425a81
 		jas_matrix_destroy(data[i]);
425a81
+		data[i] = 0;
425a81
 	}
425a81
 
425a81
 	return 0;
425a81
+
425a81
+error:
425a81
+	for (i = 0; i < numcmpts; ++i) {
425a81
+		if (data[i]) {
425a81
+			jas_matrix_destroy(data[i]);
425a81
+		}
425a81
+	}
425a81
+	return -1;
425a81
 }
425a81
 
425a81
 static int ras_puthdr(jas_stream_t *out, ras_hdr_t *hdr)