diff --git a/src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs b/src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs index db7719019b..b5ca4c26e9 100644 --- a/src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs +++ b/src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs @@ -1474,8 +1474,17 @@ internal sealed class BmpDecoderCore : ImageDecoderCore /// The stream position where the info header begins. private void ReadIccProfile(BufferedReadStream stream, ImageMetadata imageMetadata, long infoHeaderStart) { + long profileStart = infoHeaderStart + this.infoHeader.ProfileData; + if (this.infoHeader.ProfileData < 0 || + this.infoHeader.ProfileSize <= 0 || + profileStart > stream.Length || + this.infoHeader.ProfileSize > stream.Length - profileStart) + { + BmpThrowHelper.ThrowInvalidImageContentException("Not enough data to read BMP ICC profile."); + } + byte[] iccProfileData = new byte[this.infoHeader.ProfileSize]; - stream.Position = infoHeaderStart + this.infoHeader.ProfileData; + stream.Position = profileStart; if (stream.Read(iccProfileData) != iccProfileData.Length) { diff --git a/tests/ImageSharp.Tests/Formats/Bmp/BmpDecoderTests.cs b/tests/ImageSharp.Tests/Formats/Bmp/BmpDecoderTests.cs index e85c6bcdf7..ce15c91f0b 100644 --- a/tests/ImageSharp.Tests/Formats/Bmp/BmpDecoderTests.cs +++ b/tests/ImageSharp.Tests/Formats/Bmp/BmpDecoderTests.cs @@ -34,6 +34,20 @@ public class BmpDecoderTests { RLE8, 2835, 2835, PixelResolutionUnit.PixelsPerMeter } }; + [Fact] + public void Decode_WithProfileLargerThanRemainingData_ThrowsInStrictMode() + { + byte[] payload = Convert.FromHexString( + "424D8E000000000000008A0000007C0000000100000001000000010018000000" + + "0000000000000000000000000000000000000000000000000000000000000000" + + "0000000000000000000000000000000000000000000000000000000000000000" + + "000000000000000000000000000000000000000000000000000000000000C800" + + "00000000004000000000000000"); + DecoderOptions options = new() { SegmentIntegrityHandling = SegmentIntegrityHandling.Strict }; + + Assert.Throws(() => Image.Load(options, payload)); + } + [Theory] [WithFileCollection(nameof(MiscBmpFiles), PixelTypes.Rgba32)] public void BmpDecoder_CanDecode_MiscellaneousBitmaps(TestImageProvider provider) diff --git a/tests/ImageSharp.Tests/Formats/WebP/WebpMetaDataTests.cs b/tests/ImageSharp.Tests/Formats/WebP/WebpMetaDataTests.cs index 4092abfe69..10678273bb 100644 --- a/tests/ImageSharp.Tests/Formats/WebP/WebpMetaDataTests.cs +++ b/tests/ImageSharp.Tests/Formats/WebP/WebpMetaDataTests.cs @@ -238,4 +238,14 @@ public class WebpMetaDataTests Assert.Throws(() => Image.Load(payload)); Assert.Throws(() => Image.Identify(payload)); } + + [Fact] + public void Decode_WithIccChunkLargerThanRemainingData_ThrowsInvalidImageContentException() + { + byte[] payload = Convert.FromHexString( + "524946460000000057454250565038580A00000020000000010000010000494343500000004000000000"); + + Assert.Throws(() => Image.Load(payload)); + Assert.Throws(() => Image.Identify(payload)); + } }