From 7eb386da5ba35033fb6599c0c89aa3f6c2513c14 Mon Sep 17 00:00:00 2001 From: CentOS Sources Date: Sep 27 2022 11:11:05 +0000 Subject: import poppler-21.01.0-13.el9 --- diff --git a/SOURCES/poppler-21.01.0-hints.patch b/SOURCES/poppler-21.01.0-hints.patch new file mode 100644 index 0000000..85becf3 --- /dev/null +++ b/SOURCES/poppler-21.01.0-hints.patch @@ -0,0 +1,58 @@ +From 81044c64b9ed9a10ae82a28bac753060bdfdac74 Mon Sep 17 00:00:00 2001 +From: Albert Astals Cid +Date: Tue, 15 Mar 2022 15:14:32 +0100 +Subject: Hints::readTables: bail out if we run out of file when reading + +Fixes #1230 + +diff --git a/poppler/Hints.cc b/poppler/Hints.cc +index 79f04088..4707e1c6 100644 +--- a/poppler/Hints.cc ++++ b/poppler/Hints.cc +@@ -5,7 +5,7 @@ + // This file is licensed under the GPLv2 or later + // + // Copyright 2010, 2012 Hib Eris +-// Copyright 2010, 2011, 2013, 2014, 2016-2019 Albert Astals Cid ++// Copyright 2010, 2011, 2013, 2014, 2016-2019, 2021, 2022 Albert Astals Cid + // Copyright 2010, 2013 Pino Toscano + // Copyright 2013 Adrian Johnson + // Copyright 2014 Fabio D'Urso +@@ -189,21 +189,31 @@ void Hints::readTables(BaseStream *str, Linearization *linearization, XRef *xref + char *p = &buf[0]; + + if (hintsOffset && hintsLength) { +- Stream *s = str->makeSubStream(hintsOffset, false, hintsLength, Object(objNull)); ++ std::unique_ptr s(str->makeSubStream(hintsOffset, false, hintsLength, Object(objNull))); + s->reset(); + for (unsigned int i = 0; i < hintsLength; i++) { +- *p++ = s->getChar(); ++ const int c = s->getChar(); ++ if (unlikely(c == EOF)) { ++ error(errSyntaxWarning, -1, "Found EOF while reading hints"); ++ ok = false; ++ return; ++ } ++ *p++ = c; + } +- delete s; + } + + if (hintsOffset2 && hintsLength2) { +- Stream *s = str->makeSubStream(hintsOffset2, false, hintsLength2, Object(objNull)); ++ std::unique_ptr s(str->makeSubStream(hintsOffset2, false, hintsLength2, Object(objNull))); + s->reset(); + for (unsigned int i = 0; i < hintsLength2; i++) { +- *p++ = s->getChar(); ++ const int c = s->getChar(); ++ if (unlikely(c == EOF)) { ++ error(errSyntaxWarning, -1, "Found EOF while reading hints2"); ++ ok = false; ++ return; ++ } ++ *p++ = c; + } +- delete s; + } + + MemStream *memStream = new MemStream(&buf[0], 0, bufLength, Object(objNull)); diff --git a/SPECS/poppler.spec b/SPECS/poppler.spec index 56b52d7..fc8e492 100644 --- a/SPECS/poppler.spec +++ b/SPECS/poppler.spec @@ -3,7 +3,7 @@ Summary: PDF rendering library Name: poppler Version: 21.01.0 -Release: 12%{?dist} +Release: 13%{?dist} License: (GPLv2 or GPLv3) and GPLv2+ and LGPLv2+ and MIT URL: http://poppler.freedesktop.org/ Source0: http://poppler.freedesktop.org/poppler-%{version}.tar.xz @@ -29,6 +29,9 @@ Patch5: poppler-21.01.0-show-annotation-text.patch # https://bugzilla.redhat.com/show_bug.cgi?id=1967967 Patch6: poppler-21.01.0-covscan.patch +# https://bugzilla.redhat.com/show_bug.cgi?id=2087190 +Patch7: poppler-21.01.0-hints.patch + BuildRequires: make BuildRequires: cmake BuildRequires: gcc-c++ @@ -222,6 +225,11 @@ test "$(pkg-config --modversion poppler-qt5)" = "%{version}" %{_mandir}/man1/* %changelog +* Fri Jun 17 2022 Marek Kasik - 21.01.0-13 +- Don't run out of file for Hints +- Rebuild for #2096451 +- Resolves: #2090970, #2096451 + * Tue Aug 10 2021 Mohan Boddu - 21.01.0-12 - Rebuilt for IMA sigs, glibc 2.34, aarch64 flags Related: rhbz#1991688