From f1c2d419cb6a02a64b03f0e5073b219eec0b3472 Mon Sep 17 00:00:00 2001 From: Andrew Brygin Date: Thu, 17 Feb 2011 13:42:26 +0300 Subject: [PATCH] 7018912: [parfait] potential buffer overruns in imageio jpeg Reviewed-by: jgodinez, prr --- jdk/src/share/native/sun/awt/image/jpeg/imageioJPEG.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/jdk/src/share/native/sun/awt/image/jpeg/imageioJPEG.c b/jdk/src/share/native/sun/awt/image/jpeg/imageioJPEG.c index e9c98702366..04a87fd1cac 100644 --- a/jdk/src/share/native/sun/awt/image/jpeg/imageioJPEG.c +++ b/jdk/src/share/native/sun/awt/image/jpeg/imageioJPEG.c @@ -1846,7 +1846,7 @@ Java_com_sun_imageio_plugins_jpeg_JPEGImageReader_readImage cinfo = (j_decompress_ptr) data->jpegObj; - if ((numBands < 1) || + if ((numBands < 1) || (numBands > MAX_BANDS) || (sourceXStart < 0) || (sourceXStart >= (jint)cinfo->image_width) || (sourceYStart < 0) || (sourceYStart >= (jint)cinfo->image_height) || (sourceWidth < 1) || (sourceWidth > (jint)cinfo->image_width) ||