libtiff: add patch for CVE-2022-48281

Upstream issue:
https://gitlab.com/libtiff/libtiff/-/issues/488
This commit is contained in:
Thomas Gerbet
2023-01-30 22:03:18 +01:00
committed by Robert Scott
parent 7e5ab28a24
commit bf18393ed3
2 changed files with 17 additions and 0 deletions

View File

@@ -0,0 +1,16 @@
Based on upstream d1b6b9c1b3cae2d9e37754506c1ad8f4f7b646b5, adjusted for
formatting differences in 4.4.0
diff --git a/tools/tiffcrop.c b/tools/tiffcrop.c
index 5ebb30ae..698fb1cb 100644
--- a/tools/tiffcrop.c
+++ b/tools/tiffcrop.c
@@ -7735,7 +7735,7 @@ processCropSelections(struct image_data *image, struct crop_mask *crop,
crop_buff = (unsigned char *)limitMalloc(cropsize + NUM_BUFF_OVERSIZE_BYTES);
else
{
- prev_cropsize = seg_buffs[0].size;
+ prev_cropsize = seg_buffs[i].size;
if (prev_cropsize < cropsize)
{
next_buff = _TIFFrealloc(crop_buff, cropsize + NUM_BUFF_OVERSIZE_BYTES);

View File

@@ -62,6 +62,7 @@ stdenv.mkDerivation rec {
url = "https://gitlab.com/libtiff/libtiff/-/commit/227500897dfb07fb7d27f7aa570050e62617e3be.patch";
sha256 = "sha256-pgItgS+UhMjoSjkDJH5y7iGFZ+yxWKqlL7BdT2mFcH0=";
})
./4.4.0-CVE-2022-48281.patch
];
postPatch = ''