32322450 Security Vulnerability - heap buffer overflow in

libgiftranscode.so

* No range checking was done on the background color index.
Add range checking and bail if the color index is out of range.

Test: Manual
- tested sending the gif attached in the bug.
- tested sending a 3.5mb gif to verify the gif transcoding was
taking place.
- tested on arm64, arm, and x86 devices.

Change-Id: I0fd2141436e506a3dc2da04c8ede4701e2a57d19
This commit is contained in:
Tom Taylor
2016-11-30 14:24:41 -08:00
parent 70e0cbfe48
commit 0bc4f2ff03

View File

@@ -274,6 +274,11 @@ bool GifTranscoder::resizeBoxFilter(GifFileType* gifIn, GifFileType* gifOut) {
// matches what libframesequence (Rastermill) does.
if (imageIndex == 0 && gifIn->SColorMap) {
if (gcb.TransparentColor == NO_TRANSPARENT_COLOR) {
if (gifIn->SBackGroundColor < 0 ||
gifIn->SBackGroundColor >= gifIn->SColorMap->ColorCount) {
LOGE("SBackGroundColor overflow");
return false;
}
GifColorType bgColorIndex =
gifIn->SColorMap->Colors[gifIn->SBackGroundColor];
bgColor = gifColorToColorARGB(bgColorIndex);