Fix xbm image format handler: properly reject invalid files
The read_xbm_header() function is used to check for valid file header, containing valid width and height values. But in case of an invalid file, the check could depend on uninitialized variables. Change-Id: I9f933ed6e38d86109e5b5a8d55fe763ab928d749 Reviewed-by: Allan Sandfeld Jensen <allan.jensen@qt.io>bb10
parent
0736e050cb
commit
e96641d881
|
|
@ -97,6 +97,8 @@ static bool read_xbm_header(QIODevice *device, int& w, int& h)
|
|||
if (r1.indexIn(sbuf) == 0 &&
|
||||
r2.indexIn(sbuf, r1.matchedLength()) == r1.matchedLength())
|
||||
w = QByteArray(&buf[r1.matchedLength()]).trimmed().toInt();
|
||||
else
|
||||
return false;
|
||||
|
||||
// "#define .._height <num>"
|
||||
readBytes = device->readLine(buf, buflen);
|
||||
|
|
@ -109,6 +111,8 @@ static bool read_xbm_header(QIODevice *device, int& w, int& h)
|
|||
if (r1.indexIn(sbuf) == 0 &&
|
||||
r2.indexIn(sbuf, r1.matchedLength()) == r1.matchedLength())
|
||||
h = QByteArray(&buf[r1.matchedLength()]).trimmed().toInt();
|
||||
else
|
||||
return false;
|
||||
|
||||
// format error
|
||||
if (w <= 0 || w > 32767 || h <= 0 || h > 32767)
|
||||
|
|
|
|||
Loading…
Reference in New Issue