1
Official patch http://www.foolabs.com/xpdf/xpdf-3.02pl2.patch
3
Update of xpdfVersion in xpdf-3.02/xpdf/config.h
5
diff -ur -N xpdf-3.02.orig/xpdf/Stream.cc xpdf-3.02/xpdf/Stream.cc
6
--- xpdf-3.02.orig/xpdf/Stream.cc 2007-08-01 10:34:31.000000000 +0200
7
+++ xpdf-3.02/xpdf/Stream.cc 2007-11-12 13:27:21.000000000 +0100
8
@@ -1243,23 +1243,26 @@
13
- if (columns + 4 <= 0) {
14
- columns = INT_MAX - 4;
15
+ } else if (columns > INT_MAX - 2) {
16
+ columns = INT_MAX - 2;
19
endOfBlock = endOfBlockA;
21
- refLine = (short *)gmallocn(columns + 3, sizeof(short));
22
- codingLine = (short *)gmallocn(columns + 2, sizeof(short));
23
+ // 0 <= codingLine[0] < codingLine[1] < ... < codingLine[n] = columns
24
+ // ---> max codingLine size = columns + 1
25
+ // refLine has one extra guard entry at the end
26
+ // ---> max refLine size = columns + 2
27
+ codingLine = (int *)gmallocn(columns + 1, sizeof(int));
28
+ refLine = (int *)gmallocn(columns + 2, sizeof(int));
32
nextLine2D = encoding < 0;
35
- codingLine[1] = refLine[2] = columns;
37
+ codingLine[0] = columns;
45
nextLine2D = encoding < 0;
48
- codingLine[1] = columns;
50
+ codingLine[0] = columns;
55
// skip any initial zero bits and end-of-line marker, and get the 2D
56
@@ -1297,211 +1300,230 @@
60
+inline void CCITTFaxStream::addPixels(int a1, int blackPixels) {
61
+ if (a1 > codingLine[a0i]) {
63
+ error(getPos(), "CCITTFax row is wrong length (%d)", a1);
67
+ if ((a0i & 1) ^ blackPixels) {
70
+ codingLine[a0i] = a1;
74
+inline void CCITTFaxStream::addPixelsNeg(int a1, int blackPixels) {
75
+ if (a1 > codingLine[a0i]) {
77
+ error(getPos(), "CCITTFax row is wrong length (%d)", a1);
81
+ if ((a0i & 1) ^ blackPixels) {
84
+ codingLine[a0i] = a1;
85
+ } else if (a1 < codingLine[a0i]) {
87
+ error(getPos(), "Invalid CCITTFax code");
91
+ while (a0i > 0 && a1 <= codingLine[a0i - 1]) {
94
+ codingLine[a0i] = a1;
98
int CCITTFaxStream::lookChar() {
99
short code1, code2, code3;
104
+ int b1i, blackPixels, i, bits;
107
- // if at eof just return EOF
108
- if (eof && codingLine[a0] >= columns) {
116
- if (codingLine[a0] >= columns) {
117
+ if (outputBits == 0) {
119
+ // if at eof just return EOF
129
- // a0New = current position in coding line (0 <= a0New <= columns)
130
- // codingLine[a0] = last change in coding line
131
- // (black-to-white if a0 is even,
132
- // white-to-black if a0 is odd)
133
- // refLine[b1] = next change in reference line of opposite color
136
- // 0 <= codingLine[a0] <= a0New
137
- // <= refLine[b1] <= refLine[b1+1] <= columns
138
- // 0 <= a0 <= columns+1
140
- // refLine[n] = refLine[n+1] = columns
141
- // -- for some 1 <= n <= columns+1
143
- // 0 = codingLine[0] <= codingLine[1] < codingLine[2] < ...
144
- // < codingLine[n-1] < codingLine[n] = columns
145
- // -- where 1 <= n <= columns+1
146
for (i = 0; codingLine[i] < columns; ++i) {
147
refLine[i] = codingLine[i];
149
- refLine[i] = refLine[i + 1] = columns;
151
- a0New = codingLine[a0 = 0] = 0;
153
+ refLine[i++] = columns;
154
+ refLine[i] = columns;
160
+ // refLine[b1i-1] <= codingLine[a0i] < refLine[b1i] < refLine[b1i+1]
162
+ // exception at left edge:
163
+ // codingLine[a0i = 0] = refLine[b1i = 0] = 0 is possible
164
+ // exception at right edge:
165
+ // refLine[b1i] = refLine[b1i+1] = columns is possible
166
+ while (codingLine[a0i] < columns) {
167
code1 = getTwoDimCode();
170
- if (refLine[b1] < columns) {
171
- a0New = refLine[b1 + 1];
173
+ addPixels(refLine[b1i + 1], blackPixels);
174
+ if (refLine[b1i + 1] < columns) {
179
- if ((a0 & 1) == 0) {
184
- code1 += code3 = getWhiteCode();
185
+ code1 += code3 = getBlackCode();
186
} while (code3 >= 64);
188
- code2 += code3 = getBlackCode();
189
+ code2 += code3 = getWhiteCode();
190
} while (code3 >= 64);
194
- code1 += code3 = getBlackCode();
195
+ code1 += code3 = getWhiteCode();
196
} while (code3 >= 64);
198
- code2 += code3 = getWhiteCode();
199
+ code2 += code3 = getBlackCode();
200
} while (code3 >= 64);
202
- if (code1 > 0 || code2 > 0) {
203
- if (a0New + code1 <= columns) {
204
- codingLine[a0 + 1] = a0New + code1;
206
- codingLine[a0 + 1] = columns;
209
- if (codingLine[a0] + code2 <= columns) {
210
- codingLine[a0 + 1] = codingLine[a0] + code2;
212
- codingLine[a0 + 1] = columns;
215
- a0New = codingLine[a0];
216
- while (refLine[b1] <= a0New && refLine[b1] < columns) {
218
+ addPixels(codingLine[a0i] + code1, blackPixels);
219
+ if (codingLine[a0i] < columns) {
220
+ addPixels(codingLine[a0i] + code2, blackPixels ^ 1);
222
+ while (refLine[b1i] <= codingLine[a0i] && refLine[b1i] < columns) {
227
+ addPixels(refLine[b1i] + 3, blackPixels);
229
+ if (codingLine[a0i] < columns) {
231
+ while (refLine[b1i] <= codingLine[a0i] && refLine[b1i] < columns) {
237
- if (refLine[b1] < columns) {
238
- a0New = codingLine[++a0] = refLine[b1];
240
- while (refLine[b1] <= a0New && refLine[b1] < columns) {
243
+ addPixels(refLine[b1i] + 2, blackPixels);
245
+ if (codingLine[a0i] < columns) {
247
+ while (refLine[b1i] <= codingLine[a0i] && refLine[b1i] < columns) {
251
- a0New = codingLine[++a0] = columns;
255
- if (refLine[b1] + 1 < columns) {
256
- a0New = codingLine[++a0] = refLine[b1] + 1;
258
- while (refLine[b1] <= a0New && refLine[b1] < columns) {
260
+ addPixels(refLine[b1i] + 1, blackPixels);
262
+ if (codingLine[a0i] < columns) {
264
+ while (refLine[b1i] <= codingLine[a0i] && refLine[b1i] < columns) {
268
- a0New = codingLine[++a0] = columns;
272
- if (refLine[b1] - 1 > a0New || (a0 == 0 && refLine[b1] == 1)) {
273
- a0New = codingLine[++a0] = refLine[b1] - 1;
275
- while (refLine[b1] <= a0New && refLine[b1] < columns) {
278
+ addPixels(refLine[b1i], blackPixels);
280
+ if (codingLine[a0i] < columns) {
282
+ while (refLine[b1i] <= codingLine[a0i] && refLine[b1i] < columns) {
288
- if (refLine[b1] + 2 < columns) {
289
- a0New = codingLine[++a0] = refLine[b1] + 2;
291
- while (refLine[b1] <= a0New && refLine[b1] < columns) {
294
+ addPixelsNeg(refLine[b1i] - 3, blackPixels);
296
+ if (codingLine[a0i] < columns) {
302
+ while (refLine[b1i] <= codingLine[a0i] && refLine[b1i] < columns) {
306
- a0New = codingLine[++a0] = columns;
310
- if (refLine[b1] - 2 > a0New || (a0 == 0 && refLine[b1] == 2)) {
311
- a0New = codingLine[++a0] = refLine[b1] - 2;
313
- while (refLine[b1] <= a0New && refLine[b1] < columns) {
315
+ addPixelsNeg(refLine[b1i] - 2, blackPixels);
317
+ if (codingLine[a0i] < columns) {
326
- if (refLine[b1] + 3 < columns) {
327
- a0New = codingLine[++a0] = refLine[b1] + 3;
329
- while (refLine[b1] <= a0New && refLine[b1] < columns) {
331
+ while (refLine[b1i] <= codingLine[a0i] && refLine[b1i] < columns) {
335
- a0New = codingLine[++a0] = columns;
339
- if (refLine[b1] - 3 > a0New || (a0 == 0 && refLine[b1] == 3)) {
340
- a0New = codingLine[++a0] = refLine[b1] - 3;
342
- while (refLine[b1] <= a0New && refLine[b1] < columns) {
345
+ addPixelsNeg(refLine[b1i] - 1, blackPixels);
347
+ if (codingLine[a0i] < columns) {
353
+ while (refLine[b1i] <= codingLine[a0i] && refLine[b1i] < columns) {
359
+ addPixels(columns, 0);
361
- codingLine[a0 = 0] = columns;
365
error(getPos(), "Bad 2D code %04x in CCITTFax stream", code1);
366
+ addPixels(columns, 0);
370
- } while (codingLine[a0] < columns);
375
- codingLine[a0 = 0] = 0;
380
+ while (codingLine[a0i] < columns) {
383
- code1 += code3 = getWhiteCode();
384
- } while (code3 >= 64);
385
- codingLine[a0+1] = codingLine[a0] + code1;
387
- if (codingLine[a0] >= columns) {
392
- code2 += code3 = getBlackCode();
393
- } while (code3 >= 64);
394
- codingLine[a0+1] = codingLine[a0] + code2;
396
- if (codingLine[a0] >= columns) {
400
+ code1 += code3 = getBlackCode();
401
+ } while (code3 >= 64);
404
+ code1 += code3 = getWhiteCode();
405
+ } while (code3 >= 64);
407
+ addPixels(codingLine[a0i] + code1, blackPixels);
412
- if (codingLine[a0] != columns) {
413
- error(getPos(), "CCITTFax row is wrong length (%d)", codingLine[a0]);
414
- // force the row to be the correct length
415
- while (codingLine[a0] > columns) {
418
- codingLine[++a0] = columns;
422
// byte-align the row
425
@@ -1560,14 +1582,17 @@
426
// this if we know the stream contains end-of-line markers because
427
// the "just plow on" technique tends to work better otherwise
428
} else if (err && endOfLine) {
431
+ code1 = lookBits(13);
436
+ if ((code1 >> 1) == 0x001) {
440
- code1 = lookBits(13);
441
- } while ((code1 >> 1) != 0x001);
446
@@ -1575,11 +1600,11 @@
451
- outputBits = codingLine[1] - codingLine[0];
452
- if (outputBits == 0) {
454
- outputBits = codingLine[2] - codingLine[1];
455
+ // set up for output
456
+ if (codingLine[0] > 0) {
457
+ outputBits = codingLine[a0i = 0];
459
+ outputBits = codingLine[a0i = 1];
463
@@ -1587,39 +1612,43 @@
466
if (outputBits >= 8) {
467
- ret = ((a0 & 1) == 0) ? 0xff : 0x00;
468
- if ((outputBits -= 8) == 0) {
470
- if (codingLine[a0] < columns) {
471
- outputBits = codingLine[a0 + 1] - codingLine[a0];
473
+ buf = (a0i & 1) ? 0x00 : 0xff;
475
+ if (outputBits == 0 && codingLine[a0i] < columns) {
477
+ outputBits = codingLine[a0i] - codingLine[a0i - 1];
484
if (outputBits > bits) {
487
- if ((a0 & 1) == 0) {
488
- ret |= 0xff >> (8 - i);
491
+ buf |= 0xff >> (8 - bits);
494
+ outputBits -= bits;
498
- bits -= outputBits;
499
- if ((a0 & 1) == 0) {
500
- ret |= (0xff >> (8 - i)) << bits;
501
+ buf <<= outputBits;
503
+ buf |= 0xff >> (8 - outputBits);
505
+ bits -= outputBits;
508
- if (codingLine[a0] < columns) {
509
- outputBits = codingLine[a0 + 1] - codingLine[a0];
510
+ if (codingLine[a0i] < columns) {
512
+ outputBits = codingLine[a0i] - codingLine[a0i - 1];
513
+ } else if (bits > 0) {
518
- } while (bits > 0 && codingLine[a0] < columns);
524
- buf = black ? (ret ^ 0xff) : ret;
528
@@ -1661,6 +1690,9 @@
529
code = 0; // make gcc happy
535
if ((code >> 5) == 0) {
536
p = &whiteTab1[code];
538
@@ -1673,6 +1705,9 @@
540
for (n = 1; n <= 9; ++n) {
548
@@ -1684,6 +1719,9 @@
550
for (n = 11; n <= 12; ++n) {
558
@@ -1709,9 +1747,12 @@
559
code = 0; // make gcc happy
565
if ((code >> 7) == 0) {
566
p = &blackTab1[code];
567
- } else if ((code >> 9) == 0) {
568
+ } else if ((code >> 9) == 0 && (code >> 7) != 0) {
569
p = &blackTab2[(code >> 1) - 64];
571
p = &blackTab3[code >> 7];
572
@@ -1723,6 +1764,9 @@
574
for (n = 2; n <= 6; ++n) {
582
@@ -1734,6 +1778,9 @@
584
for (n = 7; n <= 12; ++n) {
592
@@ -1747,6 +1794,9 @@
594
for (n = 10; n <= 13; ++n) {
602
@@ -1961,6 +2011,12 @@
603
// allocate a buffer for the whole image
604
bufWidth = ((width + mcuWidth - 1) / mcuWidth) * mcuWidth;
605
bufHeight = ((height + mcuHeight - 1) / mcuHeight) * mcuHeight;
606
+ if (bufWidth <= 0 || bufHeight <= 0 ||
607
+ bufWidth > INT_MAX / bufWidth / (int)sizeof(int)) {
608
+ error(getPos(), "Invalid image size in DCT stream");
612
for (i = 0; i < numComps; ++i) {
613
frameBuf[i] = (int *)gmallocn(bufWidth * bufHeight, sizeof(int));
614
memset(frameBuf[i], 0, bufWidth * bufHeight * sizeof(int));
615
@@ -3036,6 +3092,11 @@
617
scanInfo.firstCoeff = str->getChar();
618
scanInfo.lastCoeff = str->getChar();
619
+ if (scanInfo.firstCoeff < 0 || scanInfo.lastCoeff > 63 ||
620
+ scanInfo.firstCoeff > scanInfo.lastCoeff) {
621
+ error(getPos(), "Bad DCT coefficient numbers in scan info block");
625
scanInfo.ah = (c >> 4) & 0x0f;
626
scanInfo.al = c & 0x0f;
627
diff -ur -N xpdf-3.02.orig/xpdf/Stream.h xpdf-3.02/xpdf/Stream.h
628
--- xpdf-3.02.orig/xpdf/Stream.h 2007-02-27 23:05:52.000000000 +0100
629
+++ xpdf-3.02/xpdf/Stream.h 2007-11-12 13:27:21.000000000 +0100
630
@@ -528,13 +528,15 @@
631
int row; // current row
632
int inputBuf; // input buffer
633
int inputBits; // number of bits in input buffer
634
- short *refLine; // reference line changing elements
635
- int b1; // index into refLine
636
- short *codingLine; // coding line changing elements
637
- int a0; // index into codingLine
638
+ int *codingLine; // coding line changing elements
639
+ int *refLine; // reference line changing elements
640
+ int a0i; // index into codingLine
641
+ GBool err; // error on current line
642
int outputBits; // remaining ouput bits
643
int buf; // character buffer
645
+ void addPixels(int a1, int black);
646
+ void addPixelsNeg(int a1, int black);
647
short getTwoDimCode();
648
short getWhiteCode();
649
short getBlackCode();
650
diff -ur -N xpdf-3.02.orig/xpdf/config.h xpdf-3.02/xpdf/config.h
651
--- xpdf-3.02.orig/xpdf/config.h 2007-08-01 10:34:31.000000000 +0200
652
+++ xpdf-3.02/xpdf/config.h 2007-11-12 13:27:21.000000000 +0100
654
//------------------------------------------------------------------------
657
-#define xpdfVersion "3.02pl1"
658
+#define xpdfVersion "3.02pl2"
659
#define xpdfVersionNum 3.02
660
#define xpdfMajorVersion 3
661
#define xpdfMinorVersion 2