diff options
author | Robin Watts <robin.watts@artifex.com> | 2014-01-08 19:36:13 +0000 |
---|---|---|
committer | Robin Watts <robin.watts@artifex.com> | 2014-01-08 19:39:06 +0000 |
commit | cc5e1c6444523ae4d7dca0feea40a41be1cbb7b2 (patch) | |
tree | 8a70bd9b5b52901a998e8a5130263faed3fd9719 /source/fitz | |
parent | 32f9ae732fc4f33ef2644a09b05d8ad35bc140ca (diff) | |
download | mupdf-cc5e1c6444523ae4d7dca0feea40a41be1cbb7b2.tar.xz |
fuzzing fix for null colorspace derefence.
Bad annotation appearance streams can cause font_recs to have invalid
values in. Avoid this partly by hardening the code against duff values,
and partly by setting sane defaults before the parsing.
This can be seen in:
33bfbe117bfef7fafc3f927acf50a2e7_signal_sigsegv_81dd96_6257_5205.pdf
Thanks to Mateusz Jurczyk and Gynvael Coldwind of the Google Security
Team for providing the example files.
Diffstat (limited to 'source/fitz')
0 files changed, 0 insertions, 0 deletions