1 | *** XRef.cc.orig Thu Jul 22 11:04:22 2004 |
---|
2 | --- XRef.cc Thu Jul 22 11:04:31 2004 |
---|
3 | *************** |
---|
4 | *** 96,102 **** |
---|
5 | } |
---|
6 | nObjects = obj1.getInt(); |
---|
7 | obj1.free(); |
---|
8 | ! if (nObjects == 0) { |
---|
9 | goto err1; |
---|
10 | } |
---|
11 | |
---|
12 | --- 96,102 ---- |
---|
13 | } |
---|
14 | nObjects = obj1.getInt(); |
---|
15 | obj1.free(); |
---|
16 | ! if (nObjects <= 0) { |
---|
17 | goto err1; |
---|
18 | } |
---|
19 | |
---|
20 | *************** |
---|
21 | *** 106,111 **** |
---|
22 | --- 106,114 ---- |
---|
23 | } |
---|
24 | first = obj1.getInt(); |
---|
25 | obj1.free(); |
---|
26 | + if (first < 0) { |
---|
27 | + goto err1; |
---|
28 | + } |
---|
29 | |
---|
30 | objs = new Object[nObjects]; |
---|
31 | objNums = (int *)gmalloc(nObjects * sizeof(int)); |
---|
32 | *************** |
---|
33 | *** 130,135 **** |
---|
34 | --- 133,144 ---- |
---|
35 | offsets[i] = obj2.getInt(); |
---|
36 | obj1.free(); |
---|
37 | obj2.free(); |
---|
38 | + if (objNums[i] < 0 || offsets[i] < 0 || |
---|
39 | + (i > 0 && offsets[i] < offsets[i-1])) { |
---|
40 | + delete parser; |
---|
41 | + gfree(offsets); |
---|
42 | + goto err1; |
---|
43 | + } |
---|
44 | } |
---|
45 | while (str->getChar() != EOF) ; |
---|
46 | delete parser; |
---|
47 | *************** |
---|
48 | *** 369,378 **** |
---|
49 | } |
---|
50 | n = obj.getInt(); |
---|
51 | obj.free(); |
---|
52 | if (first + n > size) { |
---|
53 | for (newSize = size ? 2 * size : 1024; |
---|
54 | ! first + n > newSize; |
---|
55 | newSize <<= 1) ; |
---|
56 | entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry)); |
---|
57 | for (i = size; i < newSize; ++i) { |
---|
58 | entries[i].offset = 0xffffffff; |
---|
59 | --- 378,393 ---- |
---|
60 | } |
---|
61 | n = obj.getInt(); |
---|
62 | obj.free(); |
---|
63 | + if (first < 0 || n < 0 || first + n < 0) { |
---|
64 | + goto err1; |
---|
65 | + } |
---|
66 | if (first + n > size) { |
---|
67 | for (newSize = size ? 2 * size : 1024; |
---|
68 | ! first + n > newSize && newSize > 0; |
---|
69 | newSize <<= 1) ; |
---|
70 | + if (newSize < 0) { |
---|
71 | + goto err1; |
---|
72 | + } |
---|
73 | entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry)); |
---|
74 | for (i = size; i < newSize; ++i) { |
---|
75 | entries[i].offset = 0xffffffff; |
---|
76 | *************** |
---|
77 | *** 443,449 **** |
---|
78 | |
---|
79 | // check for an 'XRefStm' key |
---|
80 | if (obj.getDict()->lookup("XRefStm", &obj2)->isInt()) { |
---|
81 | ! pos2 = obj2.getInt(); |
---|
82 | readXRef(&pos2); |
---|
83 | if (!ok) { |
---|
84 | goto err1; |
---|
85 | --- 458,464 ---- |
---|
86 | |
---|
87 | // check for an 'XRefStm' key |
---|
88 | if (obj.getDict()->lookup("XRefStm", &obj2)->isInt()) { |
---|
89 | ! pos2 = (Guint)obj2.getInt(); |
---|
90 | readXRef(&pos2); |
---|
91 | if (!ok) { |
---|
92 | goto err1; |
---|
93 | *************** |
---|
94 | *** 474,479 **** |
---|
95 | --- 489,497 ---- |
---|
96 | } |
---|
97 | newSize = obj.getInt(); |
---|
98 | obj.free(); |
---|
99 | + if (newSize < 0) { |
---|
100 | + goto err1; |
---|
101 | + } |
---|
102 | if (newSize > size) { |
---|
103 | entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry)); |
---|
104 | for (i = size; i < newSize; ++i) { |
---|
105 | *************** |
---|
106 | *** 494,499 **** |
---|
107 | --- 512,520 ---- |
---|
108 | } |
---|
109 | w[i] = obj2.getInt(); |
---|
110 | obj2.free(); |
---|
111 | + if (w[i] < 0 || w[i] > 4) { |
---|
112 | + goto err1; |
---|
113 | + } |
---|
114 | } |
---|
115 | obj.free(); |
---|
116 | |
---|
117 | *************** |
---|
118 | *** 513,525 **** |
---|
119 | } |
---|
120 | n = obj.getInt(); |
---|
121 | obj.free(); |
---|
122 | ! if (!readXRefStreamSection(xrefStr, w, first, n)) { |
---|
123 | idx.free(); |
---|
124 | goto err0; |
---|
125 | } |
---|
126 | } |
---|
127 | } else { |
---|
128 | ! if (!readXRefStreamSection(xrefStr, w, 0, size)) { |
---|
129 | idx.free(); |
---|
130 | goto err0; |
---|
131 | } |
---|
132 | --- 534,547 ---- |
---|
133 | } |
---|
134 | n = obj.getInt(); |
---|
135 | obj.free(); |
---|
136 | ! if (first < 0 || n < 0 || |
---|
137 | ! !readXRefStreamSection(xrefStr, w, first, n)) { |
---|
138 | idx.free(); |
---|
139 | goto err0; |
---|
140 | } |
---|
141 | } |
---|
142 | } else { |
---|
143 | ! if (!readXRefStreamSection(xrefStr, w, 0, newSize)) { |
---|
144 | idx.free(); |
---|
145 | goto err0; |
---|
146 | } |
---|
147 | *************** |
---|
148 | *** 551,560 **** |
---|
149 | Guint offset; |
---|
150 | int type, gen, c, newSize, i, j; |
---|
151 | |
---|
152 | if (first + n > size) { |
---|
153 | for (newSize = size ? 2 * size : 1024; |
---|
154 | ! first + n > newSize; |
---|
155 | newSize <<= 1) ; |
---|
156 | entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry)); |
---|
157 | for (i = size; i < newSize; ++i) { |
---|
158 | entries[i].offset = 0xffffffff; |
---|
159 | --- 573,588 ---- |
---|
160 | Guint offset; |
---|
161 | int type, gen, c, newSize, i, j; |
---|
162 | |
---|
163 | + if (first + n < 0) { |
---|
164 | + return gFalse; |
---|
165 | + } |
---|
166 | if (first + n > size) { |
---|
167 | for (newSize = size ? 2 * size : 1024; |
---|
168 | ! first + n > newSize && newSize > 0; |
---|
169 | newSize <<= 1) ; |
---|
170 | + if (newSize < 0) { |
---|
171 | + return gFalse; |
---|
172 | + } |
---|
173 | entries = (XRefEntry *)grealloc(entries, newSize * sizeof(XRefEntry)); |
---|
174 | for (i = size; i < newSize; ++i) { |
---|
175 | entries[i].offset = 0xffffffff; |
---|
176 | *************** |
---|
177 | *** 585,608 **** |
---|
178 | } |
---|
179 | gen = (gen << 8) + c; |
---|
180 | } |
---|
181 | ! switch (type) { |
---|
182 | ! case 0: |
---|
183 | ! entries[i].offset = offset; |
---|
184 | ! entries[i].gen = gen; |
---|
185 | ! entries[i].type = xrefEntryFree; |
---|
186 | ! break; |
---|
187 | ! case 1: |
---|
188 | ! entries[i].offset = offset; |
---|
189 | ! entries[i].gen = gen; |
---|
190 | ! entries[i].type = xrefEntryUncompressed; |
---|
191 | ! break; |
---|
192 | ! case 2: |
---|
193 | ! entries[i].offset = offset; |
---|
194 | ! entries[i].gen = gen; |
---|
195 | ! entries[i].type = xrefEntryCompressed; |
---|
196 | ! break; |
---|
197 | ! default: |
---|
198 | ! return gFalse; |
---|
199 | } |
---|
200 | } |
---|
201 | |
---|
202 | --- 613,638 ---- |
---|
203 | } |
---|
204 | gen = (gen << 8) + c; |
---|
205 | } |
---|
206 | ! if (entries[i].offset == 0xffffffff) { |
---|
207 | ! switch (type) { |
---|
208 | ! case 0: |
---|
209 | ! entries[i].offset = offset; |
---|
210 | ! entries[i].gen = gen; |
---|
211 | ! entries[i].type = xrefEntryFree; |
---|
212 | ! break; |
---|
213 | ! case 1: |
---|
214 | ! entries[i].offset = offset; |
---|
215 | ! entries[i].gen = gen; |
---|
216 | ! entries[i].type = xrefEntryUncompressed; |
---|
217 | ! break; |
---|
218 | ! case 2: |
---|
219 | ! entries[i].offset = offset; |
---|
220 | ! entries[i].gen = gen; |
---|
221 | ! entries[i].type = xrefEntryCompressed; |
---|
222 | ! break; |
---|
223 | ! default: |
---|
224 | ! return gFalse; |
---|
225 | ! } |
---|
226 | } |
---|
227 | } |
---|
228 | |
---|
229 | *************** |
---|
230 | *** 664,701 **** |
---|
231 | // look for object |
---|
232 | } else if (isdigit(*p)) { |
---|
233 | num = atoi(p); |
---|
234 | ! do { |
---|
235 | ! ++p; |
---|
236 | ! } while (*p && isdigit(*p)); |
---|
237 | ! if (isspace(*p)) { |
---|
238 | do { |
---|
239 | ++p; |
---|
240 | ! } while (*p && isspace(*p)); |
---|
241 | ! if (isdigit(*p)) { |
---|
242 | ! gen = atoi(p); |
---|
243 | do { |
---|
244 | ++p; |
---|
245 | ! } while (*p && isdigit(*p)); |
---|
246 | ! if (isspace(*p)) { |
---|
247 | do { |
---|
248 | ++p; |
---|
249 | ! } while (*p && isspace(*p)); |
---|
250 | ! if (!strncmp(p, "obj", 3)) { |
---|
251 | ! if (num >= size) { |
---|
252 | ! newSize = (num + 1 + 255) & ~255; |
---|
253 | ! entries = (XRefEntry *) |
---|
254 | ! grealloc(entries, newSize * sizeof(XRefEntry)); |
---|
255 | ! for (i = size; i < newSize; ++i) { |
---|
256 | ! entries[i].offset = 0xffffffff; |
---|
257 | ! entries[i].type = xrefEntryFree; |
---|
258 | } |
---|
259 | - size = newSize; |
---|
260 | - } |
---|
261 | - if (entries[num].type == xrefEntryFree || |
---|
262 | - gen >= entries[num].gen) { |
---|
263 | - entries[num].offset = pos - start; |
---|
264 | - entries[num].gen = gen; |
---|
265 | - entries[num].type = xrefEntryUncompressed; |
---|
266 | } |
---|
267 | } |
---|
268 | } |
---|
269 | --- 694,737 ---- |
---|
270 | // look for object |
---|
271 | } else if (isdigit(*p)) { |
---|
272 | num = atoi(p); |
---|
273 | ! if (num > 0) { |
---|
274 | do { |
---|
275 | ++p; |
---|
276 | ! } while (*p && isdigit(*p)); |
---|
277 | ! if (isspace(*p)) { |
---|
278 | do { |
---|
279 | ++p; |
---|
280 | ! } while (*p && isspace(*p)); |
---|
281 | ! if (isdigit(*p)) { |
---|
282 | ! gen = atoi(p); |
---|
283 | do { |
---|
284 | ++p; |
---|
285 | ! } while (*p && isdigit(*p)); |
---|
286 | ! if (isspace(*p)) { |
---|
287 | ! do { |
---|
288 | ! ++p; |
---|
289 | ! } while (*p && isspace(*p)); |
---|
290 | ! if (!strncmp(p, "obj", 3)) { |
---|
291 | ! if (num >= size) { |
---|
292 | ! newSize = (num + 1 + 255) & ~255; |
---|
293 | ! if (newSize < 0) { |
---|
294 | ! error(-1, "Bad object number"); |
---|
295 | ! return gFalse; |
---|
296 | ! } |
---|
297 | ! entries = (XRefEntry *) |
---|
298 | ! grealloc(entries, newSize * sizeof(XRefEntry)); |
---|
299 | ! for (i = size; i < newSize; ++i) { |
---|
300 | ! entries[i].offset = 0xffffffff; |
---|
301 | ! entries[i].type = xrefEntryFree; |
---|
302 | ! } |
---|
303 | ! size = newSize; |
---|
304 | ! } |
---|
305 | ! if (entries[num].type == xrefEntryFree || |
---|
306 | ! gen >= entries[num].gen) { |
---|
307 | ! entries[num].offset = pos - start; |
---|
308 | ! entries[num].gen = gen; |
---|
309 | ! entries[num].type = xrefEntryUncompressed; |
---|
310 | } |
---|
311 | } |
---|
312 | } |
---|
313 | } |
---|
314 | |
---|
315 | |
---|