diff options
author | Jorge Arellano Cid <jcid@dillo.org> | 2009-06-19 13:12:16 -0400 |
---|---|---|
committer | Jorge Arellano Cid <jcid@dillo.org> | 2009-06-19 13:12:16 -0400 |
commit | 30ef110e2384e0ad26c2131b9d530f53954bcde9 (patch) | |
tree | 7e2b1f7698a756d0531ebc40711948a83b471ad7 /src/png.c | |
parent | a68677c6ae0084be040ef0990a14e3a8aaaa690d (diff) | |
parent | c1ff2a39f4abae6cf587df14a9754b98c1ccc0e3 (diff) |
merge
Diffstat (limited to 'src/png.c')
-rw-r--r-- | src/png.c | 6 |
1 files changed, 6 insertions, 0 deletions
@@ -137,6 +137,12 @@ Png_datainfo_callback(png_structp png_ptr, png_infop info_ptr) png_get_IHDR(png_ptr, info_ptr, &png->width, &png->height, &bit_depth, &color_type, &interlace_type, NULL, NULL); + if (abs(png->width*png->height) > IMAGE_MAX_W * IMAGE_MAX_H) { + MSG("Png_datainfo_callback: suspicious image size request %ldx%ld\n", + png->width, png->height); + Png_error_handling(png_ptr, "Aborting..."); + return; /* not reached */ + } _MSG("Png_datainfo_callback: png->width = %ld\n" "Png_datainfo_callback: png->height = %ld\n", |