mirror of
https://github.com/Rockbox/rockbox.git
synced 2026-10-10 08:03:04 -04:00
On colour targets the image viewer hands every file its own decoder rejects to jpegp, including damaged ones, but jpegp barely checks its input. Corrupt and truncated files crashed or hung it: - At the end of the file GETC() kept returning stale bytes, so marker searches and table reads never ended. Feed EOI markers (FF D9) instead, which ends every loop, and stop calling read() there. This state is reset in OPEN(): the overlay loader does not clear .bss. - A file ending before any scan decoded as a blank image. Report it as corrupt instead. - Out of range header values were used as array indexes: Huffman and conditioning table IDs, Huffman table sizes, sampling factors, scan component counts and spectral selection. Reject them, and frames of zero width or with no components. - Invalid Huffman codes walked past the code length table, run lengths wrote past coefficient 63, and huge coefficients indexed past the IDCT clamp table. Bound all three. - An odd DAC segment length never ended its loop. - The coefficient buffer size could overflow an int. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Change-Id: I49465f38d283e159274d2f381029280cea42a8f1 |
||
|---|---|---|
| .. | ||
| BUFFILEGETC.c | ||
| FILEGETC.c | ||
| GETC.h | ||
| idct.c | ||
| idct.h | ||
| jpeg81.c | ||
| jpeg81.h | ||
| jpegp.c | ||
| jpegp.make | ||
| mempool.c | ||
| mempool.h | ||
| rb_glue.h | ||
| SOURCES | ||