Lines 41-61
Link Here
|
41 |
#endif |
41 |
#endif |
42 |
|
42 |
|
43 |
|
43 |
|
|
|
44 |
/* October 2004, source code review by Thomas Biege <thomas@suse.de> */ |
45 |
|
46 |
|
44 |
#include "XpmI.h" |
47 |
#include "XpmI.h" |
45 |
|
48 |
|
46 |
LFUNC(WriteColors, int, (char **dataptr, unsigned int *data_size, |
49 |
LFUNC(WriteColors, int, (char **dataptr, unsigned int *data_size, |
47 |
unsigned int *used_size, XpmColor *colors, |
50 |
unsigned int *used_size, XpmColor *colors, |
48 |
unsigned int ncolors, unsigned int cpp)); |
51 |
unsigned int ncolors, unsigned int cpp)); |
49 |
|
52 |
|
50 |
LFUNC(WritePixels, void, (char *dataptr, unsigned int *used_size, |
53 |
LFUNC(WritePixels, void, (char *dataptr, unsigned int data_size, |
|
|
54 |
unsigned int *used_size, |
51 |
unsigned int width, unsigned int height, |
55 |
unsigned int width, unsigned int height, |
52 |
unsigned int cpp, unsigned int *pixels, |
56 |
unsigned int cpp, unsigned int *pixels, |
53 |
XpmColor *colors)); |
57 |
XpmColor *colors)); |
54 |
|
58 |
|
55 |
LFUNC(WriteExtensions, void, (char *dataptr, unsigned int *used_size, |
59 |
LFUNC(WriteExtensions, void, (char *dataptr, unsigned int data_size, |
|
|
60 |
unsigned int *used_size, |
56 |
XpmExtension *ext, unsigned int num)); |
61 |
XpmExtension *ext, unsigned int num)); |
57 |
|
62 |
|
58 |
LFUNC(ExtensionsSize, int, (XpmExtension *ext, unsigned int num)); |
63 |
LFUNC(ExtensionsSize, unsigned int, (XpmExtension *ext, unsigned int num)); |
59 |
LFUNC(CommentsSize, int, (XpmInfo *info)); |
64 |
LFUNC(CommentsSize, int, (XpmInfo *info)); |
60 |
|
65 |
|
61 |
int |
66 |
int |
Lines 98-108
Link Here
|
98 |
|
103 |
|
99 |
#undef RETURN |
104 |
#undef RETURN |
100 |
#define RETURN(status) \ |
105 |
#define RETURN(status) \ |
|
|
106 |
do \ |
101 |
{ \ |
107 |
{ \ |
102 |
if (ptr) \ |
108 |
if (ptr) \ |
103 |
XpmFree(ptr); \ |
109 |
XpmFree(ptr); \ |
104 |
return(status); \ |
110 |
return(status); \ |
105 |
} |
111 |
} while(0) |
106 |
|
112 |
|
107 |
int |
113 |
int |
108 |
XpmCreateBufferFromXpmImage(buffer_return, image, info) |
114 |
XpmCreateBufferFromXpmImage(buffer_return, image, info) |
Lines 116-122
Link Here
|
116 |
unsigned int cmts, extensions, ext_size = 0; |
122 |
unsigned int cmts, extensions, ext_size = 0; |
117 |
unsigned int l, cmt_size = 0; |
123 |
unsigned int l, cmt_size = 0; |
118 |
char *ptr = NULL, *p; |
124 |
char *ptr = NULL, *p; |
119 |
unsigned int ptr_size, used_size; |
125 |
unsigned int ptr_size, used_size, tmp; |
120 |
|
126 |
|
121 |
*buffer_return = NULL; |
127 |
*buffer_return = NULL; |
122 |
|
128 |
|
Lines 138-144
Link Here
|
138 |
#ifdef VOID_SPRINTF |
144 |
#ifdef VOID_SPRINTF |
139 |
used_size = strlen(buf); |
145 |
used_size = strlen(buf); |
140 |
#endif |
146 |
#endif |
141 |
ptr_size = used_size + ext_size + cmt_size + 1; |
147 |
ptr_size = used_size + ext_size + cmt_size + 1; /* ptr_size can't be 0 */ |
|
|
148 |
if(ptr_size <= used_size || |
149 |
ptr_size <= ext_size || |
150 |
ptr_size <= cmt_size) |
151 |
{ |
152 |
return XpmNoMemory; |
153 |
} |
142 |
ptr = (char *) XpmMalloc(ptr_size); |
154 |
ptr = (char *) XpmMalloc(ptr_size); |
143 |
if (!ptr) |
155 |
if (!ptr) |
144 |
return XpmNoMemory; |
156 |
return XpmNoMemory; |
Lines 149-155
Link Here
|
149 |
#ifndef VOID_SPRINTF |
161 |
#ifndef VOID_SPRINTF |
150 |
used_size += |
162 |
used_size += |
151 |
#endif |
163 |
#endif |
152 |
sprintf(ptr + used_size, "/*%s*/\n", info->hints_cmt); |
164 |
snprintf(ptr + used_size, ptr_size-used_size, "/*%s*/\n", info->hints_cmt); |
153 |
#ifdef VOID_SPRINTF |
165 |
#ifdef VOID_SPRINTF |
154 |
used_size += strlen(info->hints_cmt) + 5; |
166 |
used_size += strlen(info->hints_cmt) + 5; |
155 |
#endif |
167 |
#endif |
Lines 167-173
Link Here
|
167 |
#ifndef VOID_SPRINTF |
179 |
#ifndef VOID_SPRINTF |
168 |
l += |
180 |
l += |
169 |
#endif |
181 |
#endif |
170 |
sprintf(buf + l, " %d %d", info->x_hotspot, info->y_hotspot); |
182 |
snprintf(buf + l, sizeof(buf)-l, " %d %d", info->x_hotspot, info->y_hotspot); |
171 |
#ifdef VOID_SPRINTF |
183 |
#ifdef VOID_SPRINTF |
172 |
l = strlen(buf); |
184 |
l = strlen(buf); |
173 |
#endif |
185 |
#endif |
Lines 189-194
Link Here
|
189 |
l = strlen(buf); |
201 |
l = strlen(buf); |
190 |
#endif |
202 |
#endif |
191 |
ptr_size += l; |
203 |
ptr_size += l; |
|
|
204 |
if(ptr_size <= l) |
205 |
RETURN(XpmNoMemory); |
192 |
p = (char *) XpmRealloc(ptr, ptr_size); |
206 |
p = (char *) XpmRealloc(ptr, ptr_size); |
193 |
if (!p) |
207 |
if (!p) |
194 |
RETURN(XpmNoMemory); |
208 |
RETURN(XpmNoMemory); |
Lines 201-207
Link Here
|
201 |
#ifndef VOID_SPRINTF |
215 |
#ifndef VOID_SPRINTF |
202 |
used_size += |
216 |
used_size += |
203 |
#endif |
217 |
#endif |
204 |
sprintf(ptr + used_size, "/*%s*/\n", info->colors_cmt); |
218 |
snprintf(ptr + used_size, ptr_size-used_size, "/*%s*/\n", info->colors_cmt); |
205 |
#ifdef VOID_SPRINTF |
219 |
#ifdef VOID_SPRINTF |
206 |
used_size += strlen(info->colors_cmt) + 5; |
220 |
used_size += strlen(info->colors_cmt) + 5; |
207 |
#endif |
221 |
#endif |
Lines 217-223
Link Here
|
217 |
* 4 = 1 (for '"') + 3 (for '",\n') |
231 |
* 4 = 1 (for '"') + 3 (for '",\n') |
218 |
* 1 = - 2 (because the last line does not end with ',\n') + 3 (for '};\n') |
232 |
* 1 = - 2 (because the last line does not end with ',\n') + 3 (for '};\n') |
219 |
*/ |
233 |
*/ |
220 |
ptr_size += image->height * (image->width * image->cpp + 4) + 1; |
234 |
if(image->width > UINT_MAX / image->cpp || |
|
|
235 |
(tmp = image->width * image->cpp + 4) <= 4 || |
236 |
image->height > UINT_MAX / tmp || |
237 |
(tmp = image->height * tmp + 1) <= 1 || |
238 |
(ptr_size += tmp) <= tmp) |
239 |
RETURN(XpmNoMemory); |
221 |
|
240 |
|
222 |
p = (char *) XpmRealloc(ptr, ptr_size); |
241 |
p = (char *) XpmRealloc(ptr, ptr_size); |
223 |
if (!p) |
242 |
if (!p) |
Lines 229-245
Link Here
|
229 |
#ifndef VOID_SPRINTF |
248 |
#ifndef VOID_SPRINTF |
230 |
used_size += |
249 |
used_size += |
231 |
#endif |
250 |
#endif |
232 |
sprintf(ptr + used_size, "/*%s*/\n", info->pixels_cmt); |
251 |
snprintf(ptr + used_size, ptr_size-used_size, "/*%s*/\n", info->pixels_cmt); |
233 |
#ifdef VOID_SPRINTF |
252 |
#ifdef VOID_SPRINTF |
234 |
used_size += strlen(info->pixels_cmt) + 5; |
253 |
used_size += strlen(info->pixels_cmt) + 5; |
235 |
#endif |
254 |
#endif |
236 |
} |
255 |
} |
237 |
WritePixels(ptr + used_size, &used_size, image->width, image->height, |
256 |
WritePixels(ptr + used_size, ptr_size - used_size, &used_size, image->width, image->height, |
238 |
image->cpp, image->data, image->colorTable); |
257 |
image->cpp, image->data, image->colorTable); |
239 |
|
258 |
|
240 |
/* print extensions */ |
259 |
/* print extensions */ |
241 |
if (extensions) |
260 |
if (extensions) |
242 |
WriteExtensions(ptr + used_size, &used_size, |
261 |
WriteExtensions(ptr + used_size, ptr_size-used_size, &used_size, |
243 |
info->extensions, info->nextensions); |
262 |
info->extensions, info->nextensions); |
244 |
|
263 |
|
245 |
/* close the array */ |
264 |
/* close the array */ |
Lines 250-255
Link Here
|
250 |
return (XpmSuccess); |
269 |
return (XpmSuccess); |
251 |
} |
270 |
} |
252 |
|
271 |
|
|
|
272 |
|
253 |
static int |
273 |
static int |
254 |
WriteColors(dataptr, data_size, used_size, colors, ncolors, cpp) |
274 |
WriteColors(dataptr, data_size, used_size, colors, ncolors, cpp) |
255 |
char **dataptr; |
275 |
char **dataptr; |
Lines 259-265
Link Here
|
259 |
unsigned int ncolors; |
279 |
unsigned int ncolors; |
260 |
unsigned int cpp; |
280 |
unsigned int cpp; |
261 |
{ |
281 |
{ |
262 |
char buf[BUFSIZ]; |
282 |
char buf[BUFSIZ] = {0}; |
263 |
unsigned int a, key, l; |
283 |
unsigned int a, key, l; |
264 |
char *s, *s2; |
284 |
char *s, *s2; |
265 |
char **defaults; |
285 |
char **defaults; |
Lines 269-290
Link Here
|
269 |
|
289 |
|
270 |
defaults = (char **) colors; |
290 |
defaults = (char **) colors; |
271 |
s = buf + 1; |
291 |
s = buf + 1; |
272 |
strncpy(s, *defaults++, cpp); |
292 |
if(cpp > (sizeof(buf) - (s-buf))) |
273 |
s += cpp; |
293 |
return(XpmNoMemory); |
274 |
|
294 |
strncpy(s, *defaults++, cpp); |
275 |
for (key = 1; key <= NKEYS; key++, defaults++) { |
295 |
s += cpp; |
276 |
if ((s2 = *defaults)) { |
296 |
|
277 |
#ifndef VOID_SPRINTF |
297 |
for (key = 1; key <= NKEYS; key++, defaults++) { |
278 |
s += |
298 |
if ((s2 = *defaults)) { |
279 |
#endif |
299 |
#ifndef VOID_SPRINTF |
280 |
sprintf(s, "\t%s %s", xpmColorKeys[key - 1], s2); |
300 |
s += |
281 |
#ifdef VOID_SPRINTF |
301 |
#endif |
282 |
s += strlen(s); |
302 |
/* assume C99 compliance */ |
283 |
#endif |
303 |
snprintf(s, sizeof(buf) - (s-buf), "\t%s %s", xpmColorKeys[key - 1], s2); |
284 |
} |
304 |
#ifdef VOID_SPRINTF |
285 |
} |
305 |
s += strlen(s); |
286 |
strcpy(s, "\",\n"); |
306 |
#endif |
287 |
l = s + 3 - buf; |
307 |
/* now let's check if s points out-of-bounds */ |
|
|
308 |
if((s-buf) > sizeof(buf)) |
309 |
return(XpmNoMemory); |
310 |
} |
311 |
} |
312 |
if(sizeof(buf) - (s-buf) < 4) |
313 |
return(XpmNoMemory); |
314 |
strcpy(s, "\",\n"); |
315 |
l = s + 3 - buf; |
316 |
if( *data_size >= UINT_MAX-l || |
317 |
*data_size + l <= *used_size || |
318 |
(*data_size + l - *used_size) <= sizeof(buf)) |
319 |
return(XpmNoMemory); |
288 |
s = (char *) XpmRealloc(*dataptr, *data_size + l); |
320 |
s = (char *) XpmRealloc(*dataptr, *data_size + l); |
289 |
if (!s) |
321 |
if (!s) |
290 |
return (XpmNoMemory); |
322 |
return (XpmNoMemory); |
Lines 297-304
Link Here
|
297 |
} |
329 |
} |
298 |
|
330 |
|
299 |
static void |
331 |
static void |
300 |
WritePixels(dataptr, used_size, width, height, cpp, pixels, colors) |
332 |
WritePixels(dataptr, data_size, used_size, width, height, cpp, pixels, colors) |
301 |
char *dataptr; |
333 |
char *dataptr; |
|
|
334 |
unsigned int data_size; |
302 |
unsigned int *used_size; |
335 |
unsigned int *used_size; |
303 |
unsigned int width; |
336 |
unsigned int width; |
304 |
unsigned int height; |
337 |
unsigned int height; |
Lines 309-335
Link Here
|
309 |
char *s = dataptr; |
342 |
char *s = dataptr; |
310 |
unsigned int x, y, h; |
343 |
unsigned int x, y, h; |
311 |
|
344 |
|
|
|
345 |
if(height <= 1) |
346 |
return; |
347 |
|
312 |
h = height - 1; |
348 |
h = height - 1; |
313 |
for (y = 0; y < h; y++) { |
349 |
for (y = 0; y < h; y++) { |
314 |
*s++ = '"'; |
350 |
*s++ = '"'; |
315 |
for (x = 0; x < width; x++, pixels++) { |
351 |
for (x = 0; x < width; x++, pixels++) { |
316 |
strncpy(s, colors[*pixels].string, cpp); |
352 |
if(cpp >= (data_size - (s-dataptr))) |
|
|
353 |
return; |
354 |
strncpy(s, colors[*pixels].string, cpp); /* how can we trust *pixels? :-\ */ |
317 |
s += cpp; |
355 |
s += cpp; |
318 |
} |
356 |
} |
|
|
357 |
if((data_size - (s-dataptr)) < 4) |
358 |
return; |
319 |
strcpy(s, "\",\n"); |
359 |
strcpy(s, "\",\n"); |
320 |
s += 3; |
360 |
s += 3; |
321 |
} |
361 |
} |
322 |
/* duplicate some code to avoid a test in the loop */ |
362 |
/* duplicate some code to avoid a test in the loop */ |
323 |
*s++ = '"'; |
363 |
*s++ = '"'; |
324 |
for (x = 0; x < width; x++, pixels++) { |
364 |
for (x = 0; x < width; x++, pixels++) { |
325 |
strncpy(s, colors[*pixels].string, cpp); |
365 |
if(cpp >= (data_size - (s-dataptr))) |
|
|
366 |
return; |
367 |
strncpy(s, colors[*pixels].string, cpp); /* how can we trust *pixels? */ |
326 |
s += cpp; |
368 |
s += cpp; |
327 |
} |
369 |
} |
328 |
*s++ = '"'; |
370 |
*s++ = '"'; |
329 |
*used_size += s - dataptr; |
371 |
*used_size += s - dataptr; |
330 |
} |
372 |
} |
331 |
|
373 |
|
332 |
static int |
374 |
static unsigned int |
333 |
ExtensionsSize(ext, num) |
375 |
ExtensionsSize(ext, num) |
334 |
XpmExtension *ext; |
376 |
XpmExtension *ext; |
335 |
unsigned int num; |
377 |
unsigned int num; |
Lines 338-358
Link Here
|
338 |
char **line; |
380 |
char **line; |
339 |
|
381 |
|
340 |
size = 0; |
382 |
size = 0; |
|
|
383 |
if(num == 0) |
384 |
return(0); /* ok? */ |
341 |
for (x = 0; x < num; x++, ext++) { |
385 |
for (x = 0; x < num; x++, ext++) { |
342 |
/* 11 = 10 (for ',\n"XPMEXT ') + 1 (for '"') */ |
386 |
/* 11 = 10 (for ',\n"XPMEXT ') + 1 (for '"') */ |
343 |
size += strlen(ext->name) + 11; |
387 |
size += strlen(ext->name) + 11; |
344 |
a = ext->nlines; |
388 |
a = ext->nlines; /* how can we trust ext->nlines to be not out-of-bounds? */ |
345 |
for (y = 0, line = ext->lines; y < a; y++, line++) |
389 |
for (y = 0, line = ext->lines; y < a; y++, line++) |
346 |
/* 4 = 3 (for ',\n"') + 1 (for '"') */ |
390 |
/* 4 = 3 (for ',\n"') + 1 (for '"') */ |
347 |
size += strlen(*line) + 4; |
391 |
size += strlen(*line) + 4; |
348 |
} |
392 |
} |
349 |
/* 13 is for ',\n"XPMENDEXT"' */ |
393 |
/* 13 is for ',\n"XPMENDEXT"' */ |
|
|
394 |
if(size > UINT_MAX - 13) /* unlikely */ |
395 |
return(0); |
350 |
return size + 13; |
396 |
return size + 13; |
351 |
} |
397 |
} |
352 |
|
398 |
|
353 |
static void |
399 |
static void |
354 |
WriteExtensions(dataptr, used_size, ext, num) |
400 |
WriteExtensions(dataptr, data_size, used_size, ext, num) |
355 |
char *dataptr; |
401 |
char *dataptr; |
|
|
402 |
unsigned int data_size; |
356 |
unsigned int *used_size; |
403 |
unsigned int *used_size; |
357 |
XpmExtension *ext; |
404 |
XpmExtension *ext; |
358 |
unsigned int num; |
405 |
unsigned int num; |
Lines 363-386
Link Here
|
363 |
|
410 |
|
364 |
for (x = 0; x < num; x++, ext++) { |
411 |
for (x = 0; x < num; x++, ext++) { |
365 |
#ifndef VOID_SPRINTF |
412 |
#ifndef VOID_SPRINTF |
366 |
s += 11 + |
413 |
s += |
367 |
#endif |
414 |
#endif |
368 |
sprintf(s, ",\n\"XPMEXT %s\"", ext->name); |
415 |
snprintf(s, data_size - (s-dataptr), ",\n\"XPMEXT %s\"", ext->name); |
369 |
#ifdef VOID_SPRINTF |
416 |
#ifdef VOID_SPRINTF |
370 |
s += strlen(ext->name) + 11; |
417 |
s += strlen(ext->name) + 11; |
371 |
#endif |
418 |
#endif |
372 |
a = ext->nlines; |
419 |
a = ext->nlines; |
373 |
for (y = 0, line = ext->lines; y < a; y++, line++) { |
420 |
for (y = 0, line = ext->lines; y < a; y++, line++) { |
374 |
#ifndef VOID_SPRINTF |
421 |
#ifndef VOID_SPRINTF |
375 |
s += 4 + |
422 |
s += |
376 |
#endif |
423 |
#endif |
377 |
sprintf(s, ",\n\"%s\"", *line); |
424 |
snprintf(s, data_size - (s-dataptr), ",\n\"%s\"", *line); |
378 |
#ifdef VOID_SPRINTF |
425 |
#ifdef VOID_SPRINTF |
379 |
s += strlen(*line) + 4; |
426 |
s += strlen(*line) + 4; |
380 |
#endif |
427 |
#endif |
381 |
} |
428 |
} |
382 |
} |
429 |
} |
383 |
strcpy(s, ",\n\"XPMENDEXT\""); |
430 |
strncpy(s, ",\n\"XPMENDEXT\"", data_size - (s-dataptr)-1); |
384 |
*used_size += s - dataptr + 13; |
431 |
*used_size += s - dataptr + 13; |
385 |
} |
432 |
} |
386 |
|
433 |
|
Lines 391-396
Link Here
|
391 |
int size = 0; |
438 |
int size = 0; |
392 |
|
439 |
|
393 |
/* 5 = 2 (for "/_*") + 3 (for "*_/\n") */ |
440 |
/* 5 = 2 (for "/_*") + 3 (for "*_/\n") */ |
|
|
441 |
/* wrap possible but *very* unlikely */ |
394 |
if (info->hints_cmt) |
442 |
if (info->hints_cmt) |
395 |
size += 5 + strlen(info->hints_cmt); |
443 |
size += 5 + strlen(info->hints_cmt); |
396 |
|
444 |
|