[Python-checkins] r67268 - in python/branches/release25-maint: Lib/test/test_imageop.py Misc/NEWS Modules/imageop.c

amaury.forgeotdarc python-checkins at python.org
Tue Nov 18 23:35:49 CET 2008


Author: amaury.forgeotdarc
Date: Tue Nov 18 23:35:48 2008
New Revision: 67268

Log:
#4317: Fix an Array Bounds Read in imageop.rgb2rgb8.

Backport of r67266


Modified:
   python/branches/release25-maint/Lib/test/test_imageop.py
   python/branches/release25-maint/Misc/NEWS
   python/branches/release25-maint/Modules/imageop.c

Modified: python/branches/release25-maint/Lib/test/test_imageop.py
==============================================================================
--- python/branches/release25-maint/Lib/test/test_imageop.py	(original)
+++ python/branches/release25-maint/Lib/test/test_imageop.py	Tue Nov 18 23:35:48 2008
@@ -19,6 +19,7 @@
 _VALUES = (1, 2, 2**10, 2**15-1, 2**15, 2**15+1, 2**31-2, 2**31-1)
 VALUES = tuple( -x for x in reversed(_VALUES) ) + (0,) + _VALUES
 AAAAA = "A" * 1024
+MAX_LEN = 2**20
 
 
 class InputValidationTests(unittest.TestCase):
@@ -30,7 +31,7 @@
                 strlen = abs(width * height)
                 if size:
                     strlen *= size
-                if strlen < 1024:
+                if strlen < MAX_LEN:
                     data = "A" * strlen
                 else:
                     data = AAAAA

Modified: python/branches/release25-maint/Misc/NEWS
==============================================================================
--- python/branches/release25-maint/Misc/NEWS	(original)
+++ python/branches/release25-maint/Misc/NEWS	Tue Nov 18 23:35:48 2008
@@ -12,6 +12,8 @@
 Core and builtins
 -----------------
 
+- Issue #4317: Fixed a crash in the imageop.rgb2rgb8() function.
+
 - Issue #4230: If ``__getattr__`` is a descriptor, it now functions correctly.
 
 - Issue #4048: The parser module now correctly validates relative imports.

Modified: python/branches/release25-maint/Modules/imageop.c
==============================================================================
--- python/branches/release25-maint/Modules/imageop.c	(original)
+++ python/branches/release25-maint/Modules/imageop.c	Tue Nov 18 23:35:48 2008
@@ -590,7 +590,7 @@
 	if ( !PyArg_ParseTuple(args, "s#ii", &cp, &len, &x, &y) )
 		return 0;
 
-	if ( !check_multiply_size(len*4, x, "x", y, "y", 4) )
+	if ( !check_multiply_size(len, x, "x", y, "y", 4) )
 		return 0;
 	nlen = x*y;
 	if ( !check_multiply(nlen, x, y) )


More information about the Python-checkins mailing list