Browse Source

Validate embedded profile extents

pull/3187/head
James Jackson-South 4 weeks ago
parent
commit
14ddc15e26
  1. 11
      src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs
  2. 14
      tests/ImageSharp.Tests/Formats/Bmp/BmpDecoderTests.cs
  3. 10
      tests/ImageSharp.Tests/Formats/WebP/WebpMetaDataTests.cs

11
src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs

@ -1474,8 +1474,17 @@ internal sealed class BmpDecoderCore : ImageDecoderCore
/// <param name="infoHeaderStart">The stream position where the info header begins.</param>
private void ReadIccProfile(BufferedReadStream stream, ImageMetadata imageMetadata, long infoHeaderStart)
{
long profileStart = infoHeaderStart + this.infoHeader.ProfileData;
if (this.infoHeader.ProfileData < 0 ||
this.infoHeader.ProfileSize <= 0 ||
profileStart > stream.Length ||
this.infoHeader.ProfileSize > stream.Length - profileStart)
{
BmpThrowHelper.ThrowInvalidImageContentException("Not enough data to read BMP ICC profile.");
}
byte[] iccProfileData = new byte[this.infoHeader.ProfileSize];
stream.Position = infoHeaderStart + this.infoHeader.ProfileData;
stream.Position = profileStart;
if (stream.Read(iccProfileData) != iccProfileData.Length)
{

14
tests/ImageSharp.Tests/Formats/Bmp/BmpDecoderTests.cs

@ -34,6 +34,20 @@ public class BmpDecoderTests
{ RLE8, 2835, 2835, PixelResolutionUnit.PixelsPerMeter }
};
[Fact]
public void Decode_WithProfileLargerThanRemainingData_ThrowsInStrictMode()
{
byte[] payload = Convert.FromHexString(
"424D8E000000000000008A0000007C0000000100000001000000010018000000" +
"0000000000000000000000000000000000000000000000000000000000000000" +
"0000000000000000000000000000000000000000000000000000000000000000" +
"000000000000000000000000000000000000000000000000000000000000C800" +
"00000000004000000000000000");
DecoderOptions options = new() { SegmentIntegrityHandling = SegmentIntegrityHandling.Strict };
Assert.Throws<InvalidImageContentException>(() => Image.Load(options, payload));
}
[Theory]
[WithFileCollection(nameof(MiscBmpFiles), PixelTypes.Rgba32)]
public void BmpDecoder_CanDecode_MiscellaneousBitmaps<TPixel>(TestImageProvider<TPixel> provider)

10
tests/ImageSharp.Tests/Formats/WebP/WebpMetaDataTests.cs

@ -238,4 +238,14 @@ public class WebpMetaDataTests
Assert.Throws<InvalidImageContentException>(() => Image.Load(payload));
Assert.Throws<InvalidImageContentException>(() => Image.Identify(payload));
}
[Fact]
public void Decode_WithIccChunkLargerThanRemainingData_ThrowsInvalidImageContentException()
{
byte[] payload = Convert.FromHexString(
"524946460000000057454250565038580A00000020000000010000010000494343500000004000000000");
Assert.Throws<InvalidImageContentException>(() => Image.Load(payload));
Assert.Throws<InvalidImageContentException>(() => Image.Identify(payload));
}
}

Loading…
Cancel
Save