git-svn-id: https://svn.wxwidgets.org/svn/wx/wxWidgets/trunk@60876
c3d73ce0-8a6f-49c7-b76d-
6d57e0e08775
uint32 *raster;
TIFFGetField( tif, TIFFTAG_IMAGEWIDTH, &w );
uint32 *raster;
TIFFGetField( tif, TIFFTAG_IMAGEWIDTH, &w );
(samplesInfo[0] == EXTRASAMPLE_ASSOCALPHA ||
samplesInfo[0] == EXTRASAMPLE_UNASSALPHA));
(samplesInfo[0] == EXTRASAMPLE_ASSOCALPHA ||
samplesInfo[0] == EXTRASAMPLE_UNASSALPHA));
+ // guard against integer overflow during multiplication which could result
+ // in allocating a too small buffer and then overflowing it
+ const double bytesNeeded = w * h * sizeof(uint32);
+ if ( bytesNeeded >= wxUINT32_MAX )
+ {
+ if ( verbose )
+ wxLogError( _("TIFF: Image size is abnormally big.") );
+
+ TIFFClose(tif);
+
+ return false;
+ }
- raster = (uint32*) _TIFFmalloc( npixels * sizeof(uint32) );
+ raster = (uint32*) _TIFFmalloc( bytesNeeded );