Limit PNG image dimensions.

This commit is contained in:
wolfbeast 2018-05-29 13:11:09 +02:00 committed by Roy Tam
commit 26ca4670fe

View file

@ -34,13 +34,18 @@ namespace image {
static LazyLogModule sPNGLog("PNGDecoder");
static LazyLogModule sPNGDecoderAccountingLog("PNGDecoderAccounting");
// limit image dimensions (bug #251381, #591822, #967656, and #1283961)
// Limit image dimensions.
#ifndef MOZ_PNG_MAX_WIDTH
# define MOZ_PNG_MAX_WIDTH 0x7fffffff // Unlimited
# define MOZ_PNG_MAX_WIDTH 65535
#endif
#ifndef MOZ_PNG_MAX_HEIGHT
# define MOZ_PNG_MAX_HEIGHT 0x7fffffff // Unlimited
# define MOZ_PNG_MAX_HEIGHT 65535
#endif
// Maximum area supported in pixels (W*H)
#ifndef MOZ_PNG_MAX_PIX
# define MOZ_PNG_MAX_PIX 268435456 // 256 Mpix = 16Ki x 16Ki
#endif
nsPNGDecoder::AnimFrameInfo::AnimFrameInfo()
: mDispose(DisposalMethod::KEEP)
@ -568,6 +573,13 @@ nsPNGDecoder::info_callback(png_structp png_ptr, png_infop info_ptr)
png_get_IHDR(png_ptr, info_ptr, &width, &height, &bit_depth, &color_type,
&interlace_type, &compression_type, &filter_type);
// Check sizes against cap limits and W*H
if ((width > MOZ_PNG_MAX_WIDTH) ||
(height > MOZ_PNG_MAX_HEIGHT) ||
(width * height > MOZ_PNG_MAX_PIX)) {
png_error(decoder->mPNG, "Image too large");
}
const IntRect frameRect(0, 0, width, height);
// Post our size to the superclass