From bcc1f62715f8005684ac6b798d0d54224394e975 Mon Sep 17 00:00:00 2001 From: Tom Taylor Date: Thu, 1 Dec 2016 12:20:44 -0800 Subject: [PATCH] 32322450 Security Vulnerability - heap buffer overflow in libgiftranscode.so * No range checking was done on the background color index. Add range checking and bail if the color index is out of range. * Test Manual - tested sending the gif attached in the bug. - tested sending a 3.5mb gif to verify the gif transcoding was taking place. - tested on arm64, arm, and x86 devices. Change-Id: Id16ddccf05c8472ddebc1284b2a928dafd1be551 Fixes: 32322450 --- jni/GifTranscoder.cpp | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/jni/GifTranscoder.cpp b/jni/GifTranscoder.cpp index 44fa30c..0d50770 100644 --- a/jni/GifTranscoder.cpp +++ b/jni/GifTranscoder.cpp @@ -274,6 +274,11 @@ bool GifTranscoder::resizeBoxFilter(GifFileType* gifIn, GifFileType* gifOut) { // matches what libframesequence (Rastermill) does. if (imageIndex == 0 && gifIn->SColorMap) { if (gcb.TransparentColor == NO_TRANSPARENT_COLOR) { + if (gifIn->SBackGroundColor < 0 || + gifIn->SBackGroundColor >= gifIn->SColorMap->ColorCount) { + LOGE("SBackGroundColor overflow"); + return false; + } GifColorType bgColorIndex = gifIn->SColorMap->Colors[gifIn->SBackGroundColor]; bgColor = gifColorToColorARGB(bgColorIndex);