aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJorim Jaggi <jjaggi@google.com>2016-12-07 22:46:57 +0000
committerandroid-build-merger <android-build-merger@google.com>2016-12-07 22:46:57 +0000
commite1508f990bd8465562218b76d041e31a8108379e (patch)
treee5c19c26fc748743c3956d06a2c0492610f9c3c4
parent334959c9b0415648a48de8cd4514f10aaa60ebe4 (diff)
parent890381c983b6eca60a435ebf5a4bdbd7a32660f0 (diff)
downloadlibgdx-e1508f990bd8465562218b76d041e31a8108379e.tar.gz
Fix security vulnerability
am: 890381c983 Change-Id: Ie9b51194a0ee1432cabcd2c26f3ef3b3581eb8ee
-rw-r--r--gdx/jni/gdx2d/jpgd.cpp4
1 files changed, 4 insertions, 0 deletions
diff --git a/gdx/jni/gdx2d/jpgd.cpp b/gdx/jni/gdx2d/jpgd.cpp
index 3873dfbe2..4c84a3321 100644
--- a/gdx/jni/gdx2d/jpgd.cpp
+++ b/gdx/jni/gdx2d/jpgd.cpp
@@ -2231,7 +2231,10 @@ void jpeg_decoder::make_huff_table(int index, huff_tables *pH)
for (l = 1; l <= 16; l++)
{
for (i = 1; i <= m_huff_num[index][l]; i++)
+ {
+ JPGD_ASSERT(p < 257);
huffsize[p++] = static_cast<uint8>(l);
+ }
}
huffsize[p] = 0;
@@ -2246,6 +2249,7 @@ void jpeg_decoder::make_huff_table(int index, huff_tables *pH)
{
while (huffsize[p] == si)
{
+ JPGD_ASSERT(p < 257);
huffcode[p++] = code;
code++;
}