Blame SOURCES/jasper-CVE-2016-9560.patch

94b862
Backport of the upstream commit:
94b862
94b862
From 1abc2e5a401a4bf1d5ca4df91358ce5df111f495 Mon Sep 17 00:00:00 2001
94b862
From: Michael Adams <mdadams@ece.uvic.ca>
94b862
Date: Sun, 20 Nov 2016 04:43:00 -0800
94b862
Subject: [PATCH] Fixed an array overflow problem in the JPC decoder.
94b862
94b862
diff -pruN jasper-1.900.1.orig/src/libjasper/jpc/jpc_dec.c jasper-1.900.1/src/libjasper/jpc/jpc_dec.c
94b862
--- jasper-1.900.1.orig/src/libjasper/jpc/jpc_dec.c	2017-03-30 15:00:55.000000000 +0200
94b862
+++ jasper-1.900.1/src/libjasper/jpc/jpc_dec.c	2017-03-30 17:56:05.000000000 +0200
94b862
@@ -675,7 +675,7 @@ static int jpc_dec_tileinit(jpc_dec_t *d
94b862
 	uint_fast32_t tmpxend;
94b862
 	uint_fast32_t tmpyend;
94b862
 	jpc_dec_cp_t *cp;
94b862
-	jpc_tsfb_band_t bnds[64];
94b862
+	jpc_tsfb_band_t bnds[JPC_MAXBANDS];
94b862
 	jpc_pchg_t *pchg;
94b862
 	int pchgno;
94b862
 	jpc_dec_cmpt_t *cmpt;