diff --git a/src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs b/src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs
index db7719019b..b5ca4c26e9 100644
--- a/src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs
+++ b/src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs
@@ -1474,8 +1474,17 @@ internal sealed class BmpDecoderCore : ImageDecoderCore
/// The stream position where the info header begins.
private void ReadIccProfile(BufferedReadStream stream, ImageMetadata imageMetadata, long infoHeaderStart)
{
+ long profileStart = infoHeaderStart + this.infoHeader.ProfileData;
+ if (this.infoHeader.ProfileData < 0 ||
+ this.infoHeader.ProfileSize <= 0 ||
+ profileStart > stream.Length ||
+ this.infoHeader.ProfileSize > stream.Length - profileStart)
+ {
+ BmpThrowHelper.ThrowInvalidImageContentException("Not enough data to read BMP ICC profile.");
+ }
+
byte[] iccProfileData = new byte[this.infoHeader.ProfileSize];
- stream.Position = infoHeaderStart + this.infoHeader.ProfileData;
+ stream.Position = profileStart;
if (stream.Read(iccProfileData) != iccProfileData.Length)
{
diff --git a/tests/ImageSharp.Tests/Formats/Bmp/BmpDecoderTests.cs b/tests/ImageSharp.Tests/Formats/Bmp/BmpDecoderTests.cs
index e85c6bcdf7..ce15c91f0b 100644
--- a/tests/ImageSharp.Tests/Formats/Bmp/BmpDecoderTests.cs
+++ b/tests/ImageSharp.Tests/Formats/Bmp/BmpDecoderTests.cs
@@ -34,6 +34,20 @@ public class BmpDecoderTests
{ RLE8, 2835, 2835, PixelResolutionUnit.PixelsPerMeter }
};
+ [Fact]
+ public void Decode_WithProfileLargerThanRemainingData_ThrowsInStrictMode()
+ {
+ byte[] payload = Convert.FromHexString(
+ "424D8E000000000000008A0000007C0000000100000001000000010018000000" +
+ "0000000000000000000000000000000000000000000000000000000000000000" +
+ "0000000000000000000000000000000000000000000000000000000000000000" +
+ "000000000000000000000000000000000000000000000000000000000000C800" +
+ "00000000004000000000000000");
+ DecoderOptions options = new() { SegmentIntegrityHandling = SegmentIntegrityHandling.Strict };
+
+ Assert.Throws(() => Image.Load(options, payload));
+ }
+
[Theory]
[WithFileCollection(nameof(MiscBmpFiles), PixelTypes.Rgba32)]
public void BmpDecoder_CanDecode_MiscellaneousBitmaps(TestImageProvider provider)
diff --git a/tests/ImageSharp.Tests/Formats/WebP/WebpMetaDataTests.cs b/tests/ImageSharp.Tests/Formats/WebP/WebpMetaDataTests.cs
index 4092abfe69..10678273bb 100644
--- a/tests/ImageSharp.Tests/Formats/WebP/WebpMetaDataTests.cs
+++ b/tests/ImageSharp.Tests/Formats/WebP/WebpMetaDataTests.cs
@@ -238,4 +238,14 @@ public class WebpMetaDataTests
Assert.Throws(() => Image.Load(payload));
Assert.Throws(() => Image.Identify(payload));
}
+
+ [Fact]
+ public void Decode_WithIccChunkLargerThanRemainingData_ThrowsInvalidImageContentException()
+ {
+ byte[] payload = Convert.FromHexString(
+ "524946460000000057454250565038580A00000020000000010000010000494343500000004000000000");
+
+ Assert.Throws(() => Image.Load(payload));
+ Assert.Throws(() => Image.Identify(payload));
+ }
}