From 65577375d421d7dd27d7df4c7239f44902dbf939 Mon Sep 17 00:00:00 2001 From: Even Rouault Date: Wed, 24 Dec 2014 16:57:18 +0000 Subject: [PATCH] * libtiff/tif_getimage.c: avoid divide by zero on invalid YCbCr subsampling. http://bugzilla.maptools.org/show_bug.cgi?id=2235 --- ChangeLog | 5 +++++ libtiff/tif_getimage.c | 6 +++++- 2 files changed, 10 insertions(+), 1 deletion(-) diff --git a/ChangeLog b/ChangeLog index 2054dd2e..1c9d7a3d 100644 --- a/ChangeLog +++ b/ChangeLog @@ -1,3 +1,8 @@ +2014-12-24 Even Rouault + + * libtiff/tif_getimage.c: avoid divide by zero on invalid YCbCr subsampling. + http://bugzilla.maptools.org/show_bug.cgi?id=2235 + 2014-12-24 Even Rouault * tools/tiff2pdf.c: fix buffer overflow on some YCbCr JPEG compressed images. diff --git a/libtiff/tif_getimage.c b/libtiff/tif_getimage.c index 068be6e7..36f698a7 100644 --- a/libtiff/tif_getimage.c +++ b/libtiff/tif_getimage.c @@ -1,4 +1,4 @@ -/* $Id: tif_getimage.c,v 1.83 2014-12-21 15:15:31 erouault Exp $ */ +/* $Id: tif_getimage.c,v 1.84 2014-12-24 16:57:18 erouault Exp $ */ /* * Copyright (c) 1991-1997 Sam Leffler @@ -875,6 +875,10 @@ gtStripContig(TIFFRGBAImage* img, uint32* raster, uint32 w, uint32 h) TIFFGetFieldDefaulted(tif, TIFFTAG_ROWSPERSTRIP, &rowsperstrip); TIFFGetFieldDefaulted(tif, TIFFTAG_YCBCRSUBSAMPLING, &subsamplinghor, &subsamplingver); + if( subsamplingver == 0 ) { + TIFFErrorExt(tif->tif_clientdata, TIFFFileName(tif), "Invalid vertical YCbCr subsampling"); + return (0); + } scanline = TIFFScanlineSize(tif); fromskew = (w < imagewidth ? imagewidth - w : 0); for (row = 0; row < h; row += nrow)