From 671f0d4949d412f26fba6c675cfb54b1fc170be0 Mon Sep 17 00:00:00 2001 From: Lei Zhang Date: Thu, 31 Aug 2017 11:00:54 -0700 Subject: Prevent FPDFAvail_IsDocAvail() from infinite looping. BUG=pdfium:875 Change-Id: I3cc29990f0a3398ae903bc14417ec695cca30c6c Reviewed-on: https://pdfium-review.googlesource.com/12391 Commit-Queue: Lei Zhang Reviewed-by: Art Snake Reviewed-by: Wei Li --- core/fpdfapi/parser/cpdf_data_avail.cpp | 3 ++- core/fpdfapi/parser/cpdf_data_avail.h | 1 + 2 files changed, 3 insertions(+), 1 deletion(-) (limited to 'core/fpdfapi/parser') diff --git a/core/fpdfapi/parser/cpdf_data_avail.cpp b/core/fpdfapi/parser/cpdf_data_avail.cpp index 76190fa9a9..b7ea238507 100644 --- a/core/fpdfapi/parser/cpdf_data_avail.cpp +++ b/core/fpdfapi/parser/cpdf_data_avail.cpp @@ -943,8 +943,9 @@ bool CPDF_DataAvail::CheckTrailer() { return true; } + // Prevent infinite-looping between Prev entries. uint32_t xrefpos = GetDirectInteger(pTrailerDict, "Prev"); - if (!xrefpos) { + if (!xrefpos || !m_SeenPrevPositions.insert(xrefpos).second) { m_dwPrevXRefOffset = 0; m_docStatus = PDF_DATAAVAIL_LOADALLCROSSREF; return true; diff --git a/core/fpdfapi/parser/cpdf_data_avail.h b/core/fpdfapi/parser/cpdf_data_avail.h index 1fcdaf034e..e2a4a20aa1 100644 --- a/core/fpdfapi/parser/cpdf_data_avail.h +++ b/core/fpdfapi/parser/cpdf_data_avail.h @@ -230,6 +230,7 @@ class CPDF_DataAvail final { PageNode m_PageNode; std::set m_pageMapCheckState; std::set m_pagesLoadState; + std::set m_SeenPrevPositions; std::unique_ptr m_pHintTables; bool m_bSupportHintTable; }; -- cgit v1.2.3