Browse Source

Validate decoded image dimensions

pull/3187/head
James Jackson-South 4 weeks ago
parent
commit
7781fbd879
  1. 5
      src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs
  2. 9
      src/ImageSharp/Formats/Gif/GifDecoderCore.cs
  3. 4
      src/ImageSharp/Formats/Tga/TgaDecoderCore.cs
  4. 18
      tests/ImageSharp.Tests/Formats/InvalidImageDimensionsTests.cs

5
src/ImageSharp/Formats/Bmp/BmpDecoderCore.cs

@ -1560,6 +1560,11 @@ internal sealed class BmpDecoderCore : ImageDecoderCore
this.infoHeader.Height = -this.infoHeader.Height;
}
if (this.infoHeader.Width <= 0 || this.infoHeader.Height <= 0)
{
BmpThrowHelper.ThrowInvalidImageContentException("Width and height must be greater than 0.");
}
int bytesPerColorMapEntry = 4;
int colorMapSizeBytes = -1;
if (this.infoHeader.ClrUsed == 0)

9
src/ImageSharp/Formats/Gif/GifDecoderCore.cs

@ -261,11 +261,6 @@ internal sealed class GifDecoderCore : ImageDecoderCore
this.currentLocalColorTable?.Dispose();
}
if (this.logicalScreenDescriptor.Width == 0 && this.logicalScreenDescriptor.Height == 0)
{
GifThrowHelper.ThrowNoHeader();
}
// Ignoring a malformed ancillary extension must not let identify succeed for a file
// that never contained any readable image frame data.
if (previousFrame is null)
@ -328,6 +323,10 @@ internal sealed class GifDecoderCore : ImageDecoderCore
}
this.logicalScreenDescriptor = GifLogicalScreenDescriptor.Parse(this.buffer);
if (this.logicalScreenDescriptor.Width == 0 || this.logicalScreenDescriptor.Height == 0)
{
GifThrowHelper.ThrowInvalidImageContentException("Width and height must be greater than 0.");
}
}
/// <summary>

4
src/ImageSharp/Formats/Tga/TgaDecoderCore.cs

@ -72,9 +72,9 @@ internal sealed class TgaDecoderCore : ImageDecoderCore
TgaThrowHelper.ThrowNotSupportedException($"Unknown tga colormap type {this.fileHeader.ColorMapType} found");
}
if (this.fileHeader.Width == 0 || this.fileHeader.Height == 0)
if (this.fileHeader.Width <= 0 || this.fileHeader.Height <= 0)
{
throw new UnknownImageFormatException("Width or height cannot be 0");
TgaThrowHelper.ThrowInvalidImageContentException("Width and height must be greater than 0.");
}
Image<TPixel> image = new(this.configuration, this.fileHeader.Width, this.fileHeader.Height, this.metadata);

18
tests/ImageSharp.Tests/Formats/InvalidImageDimensionsTests.cs

@ -0,0 +1,18 @@
// Copyright (c) Six Labors.
// Licensed under the Six Labors Split License.
namespace SixLabors.ImageSharp.Tests.Formats;
public class InvalidImageDimensionsTests
{
[Theory]
[InlineData("Qk1GAAAAAAAAADYAAAAoAAAAAgACAAAAAAABABgAAAAAABAAAAATCwAAEwsAAAAAAAAAAAAAAAD/AP8AAAAAAP8A/wAAAA==")]
[InlineData("R0lGODdhAgIAAIEAAAD/AP8AAAAA/wAAACwAAAQAAgACAAAIBwADABAQICAAOw==")]
[InlineData("AAACAAAAAAAAAAAAAgDCsRgAAgAAAP8A/wD/AAAA//8=")]
public void Load_WithNonPositiveDimensions_ThrowsInvalidImageContentException(string encodedData)
{
byte[] data = Convert.FromBase64String(encodedData);
Assert.Throws<InvalidImageContentException>(() => Image.Load(data));
}
}
Loading…
Cancel
Save