Re: [PATCH] src/cairo-surface-observer-private.h :

Bryce Harrington <[email protected]>
Newsgroups gmane.comp.lib.cairo
Message-ID <[email protected]>
On Thu, Jul 09, 2015 at 10:43:30AM +0530, Ashim wrote:
> "print_array" called with args "p->type" and "pattern_names" where patten_names has length 8.
> 'for loop' will try accessing 8th element at line 1587
> .
> But struct Pattern has member 'type' of the length 7.
> Hence changed the 'type' array from type[7] to type[8]
> 
> This patch will avoid out of bound access
> 
> Fixes: https://bugs.freedesktop.org/show_bug.cgi?id=91266
> 
> Signed-off-by: Ashim <[email protected]>

Good find.

Reviewed-by: Bryce Harrington <[email protected]>

To ssh://git.cairographics.org/git/cairo
   ad45e8f..498fc2f  master -> master

> ---
>  src/cairo-surface-observer-private.h |    2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/src/cairo-surface-observer-private.h b/src/cairo-surface-observer-private.h
> index 70c87db..6ed0c18 100644
> --- a/src/cairo-surface-observer-private.h
> +++ b/src/cairo-surface-observer-private.h
> @@ -62,7 +62,7 @@ struct extents {
>  };
>  
>  struct pattern {
> -    unsigned int type[7]; /* native/record/other surface/gradients */
> +    unsigned int type[8]; /* native/record/other surface/gradients */
>  };
>  
>  struct path {
> -- 
> 1.7.9.5
> 
> -- 
> cairo mailing list
> [email protected]
> http://lists.cairographics.org/mailman/listinfo/cairo
-- 
cairo mailing list
[email protected]
http://lists.cairographics.org/mailman/listinfo/cairo
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.