summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorIgnacio Casal Quinteiro <qignacio@amazon.com>2017-04-16 13:56:09 +0200
committerIgnacio Casal Quinteiro <qignacio@amazon.com>2017-04-16 13:56:09 +0200
commit9ad72875e9f08e4c519ef63d44cdbd94aa9504f7 (patch)
treeb4b6c2a5a364382f786b91909c69045419fe98c8
parent1fa1fdf73af5b2d5a05eafaba41e6ce26df4609b (diff)
downloadlibcroco-9ad72875e9f08e4c519ef63d44cdbd94aa9504f7.tar.gz
tknzr: support only max long rgb values
This fixes a possible out of bound when reading rgbs which are longer than the support MAXLONG
-rw-r--r--src/cr-tknzr.c10
1 files changed, 10 insertions, 0 deletions
diff --git a/src/cr-tknzr.c b/src/cr-tknzr.c
index 1a7cfeb..1548c35 100644
--- a/src/cr-tknzr.c
+++ b/src/cr-tknzr.c
@@ -1279,6 +1279,11 @@ cr_tknzr_parse_rgb (CRTknzr * a_this, CRRgb ** a_rgb)
status = cr_tknzr_parse_num (a_this, &num);
ENSURE_PARSING_COND ((status == CR_OK) && (num != NULL));
+ if (num->val > G_MAXLONG) {
+ status = CR_PARSING_ERROR;
+ goto error;
+ }
+
red = num->val;
cr_num_destroy (num);
num = NULL;
@@ -1298,6 +1303,11 @@ cr_tknzr_parse_rgb (CRTknzr * a_this, CRRgb ** a_rgb)
status = cr_tknzr_parse_num (a_this, &num);
ENSURE_PARSING_COND ((status == CR_OK) && (num != NULL));
+ if (num->val > G_MAXLONG) {
+ status = CR_PARSING_ERROR;
+ goto error;
+ }
+
PEEK_BYTE (a_this, 1, &next_bytes[0]);
if (next_bytes[0] == '%') {
SKIP_CHARS (a_this, 1);