Blob Blame History Raw
Backport of relevant parts of upstream commit:

From 1e84674d95353c64e5c4c0e7232ae86fd6ea813b Mon Sep 17 00:00:00 2001
From: Michael Adams <mdadams@ece.uvic.ca>
Date: Tue, 25 Oct 2016 07:01:50 -0700
Subject: [PATCH] Changed the JPC bitstream code to more gracefully handle a
 request for a larger sized integer than what can be handled (i.e., return
 with an error instead of failing an assert).

diff -pruN jasper-1.900.1.orig/src/libjasper/jpc/jpc_bs.c jasper-1.900.1/src/libjasper/jpc/jpc_bs.c
--- jasper-1.900.1.orig/src/libjasper/jpc/jpc_bs.c	2007-01-19 22:43:07.000000000 +0100
+++ jasper-1.900.1/src/libjasper/jpc/jpc_bs.c	2017-03-31 23:00:31.000000000 +0200
@@ -195,7 +195,10 @@ long jpc_bitstream_getbits(jpc_bitstream
 
 	/* We can reliably get at most 31 bits since ISO/IEC 9899 only
 	  guarantees that a long can represent values up to 2^31-1. */
-	assert(n >= 0 && n < 32);
+	//assert(n >= 0 && n < 32);
+	if (n < 0 || n >= 32) {
+		return -1;
+	}
 
 	/* Get the number of bits requested from the specified bit stream. */
 	v = 0;
@@ -215,7 +218,10 @@ int jpc_bitstream_putbits(jpc_bitstream_
 
 	/* We can reliably put at most 31 bits since ISO/IEC 9899 only
 	  guarantees that a long can represent values up to 2^31-1. */
-	assert(n >= 0 && n < 32);
+	//assert(n >= 0 && n < 32);
+	if (n < 0 || n >= 32) {
+		return EOF;
+	}
 	/* Ensure that only the bits to be output are nonzero. */
 	assert(!(v & (~JAS_ONES(n))));