From 137be1f5e45a5002a18a5e392d0f1825d901fdf7 Mon Sep 17 00:00:00 2001 From: npt-1707 Date: Thu, 17 Apr 2025 16:54:06 +0800 Subject: [PATCH] dcraw.cc: parse_qt: possible integer overflow --- rtengine/dcraw.cc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/rtengine/dcraw.cc b/rtengine/dcraw.cc index 55f637f24..b41d2fa10 100644 --- a/rtengine/dcraw.cc +++ b/rtengine/dcraw.cc @@ -7842,6 +7842,8 @@ void CLASS parse_qt (int end) while (ftell(ifp)+7 < end) { save = ftell(ifp); if ((size = get4()) < 8) return; + if ((int)size < 0) return; // 2+GB is too much + if (save + size < save) return; // 32bit overflow fread (tag, 4, 1, ifp); if (!memcmp(tag,"moov",4) || !memcmp(tag,"udta",4) ||