99 \author Original author CERL
1010 */
1111
12+ #include <limits.h>
1213#include <stdint.h>
1314#include <string.h>
1415#include <unistd.h>
@@ -98,21 +99,24 @@ static void read_data_fp_compressed(int fd, int row, unsigned char *data_buf,
9899
99100 * nbytes = fcb -> nbytes ;
100101
101- ret = G_read_compressed (fcb -> data_fd , readamount , data_buf , bufsize ,
102- fcb -> cellhd .compressed );
102+ if (readamount > INT_MAX || bufsize > INT_MAX )
103+ G_fatal_error (_ ("Compressed fp raster row for <%s> is too large" ),
104+ fcb -> name );
105+
106+ ret = G_read_compressed (fcb -> data_fd , (int )readamount , data_buf ,
107+ (int )bufsize , fcb -> cellhd .compressed );
103108 if (ret <= 0 )
104109 G_fatal_error (_ ("Error uncompressing fp raster data for row %d of "
105110 "<%s>: error code %d" ),
106111 row , fcb -> name , ret );
107112}
108113
109114static void rle_decompress (unsigned char * dst , const unsigned char * src ,
110- int nbytes , int size )
115+ int nbytes , size_t size )
111116{
112- int pairs = size / (nbytes + 1 );
113- int i ;
117+ size_t pairs = size / ((size_t )nbytes + 1 );
114118
115- for (i = 0 ; i < pairs ; i ++ ) {
119+ for (size_t i = 0 ; i < pairs ; i ++ ) {
116120 int repeat = * src ++ ;
117121 int j ;
118122
@@ -131,19 +135,32 @@ static void read_data_compressed(int fd, int row, unsigned char *data_buf,
131135 struct fileinfo * fcb = & R__ .fileinfo [fd ];
132136 off_t t1 = fcb -> row_ptr [row ];
133137 off_t t2 = fcb -> row_ptr [row + 1 ];
134- ssize_t readamount = t2 - t1 ;
138+ off_t row_size ;
139+ size_t readamount ;
135140 size_t bufsize ;
136141 unsigned char * cmp , * cmp2 ;
137142 int n ;
138143
144+ if (t2 < t1 )
145+ G_fatal_error (_ ("Invalid raster row offset for row %d of <%s>" ), row ,
146+ fcb -> name );
147+
148+ row_size = t2 - t1 ;
149+ if (row_size > SSIZE_MAX )
150+ G_fatal_error (_ ("Compressed raster row for <%s> is too large" ),
151+ fcb -> name );
152+
153+ readamount = (size_t )row_size ;
154+
139155 if (lseek (fcb -> data_fd , t1 , SEEK_SET ) == -1 )
140156 G_fatal_error (
141157 _ ("Error seeking raster data file for row %d of <%s>: %s" ), row ,
142158 fcb -> name , strerror (errno ));
143159
144160 cmp = G_malloc (readamount );
145161
146- if (read (fcb -> data_fd , cmp , readamount ) != readamount ) {
162+ ssize_t nread = read (fcb -> data_fd , cmp , readamount );
163+ if (nread < 0 || (size_t )nread != readamount ) {
147164 G_free (cmp );
148165 G_fatal_error (_ ("Error reading raster data for row %d of <%s>: %s" ),
149166 row , fcb -> name , strerror (errno ));
@@ -154,6 +171,12 @@ static void read_data_compressed(int fd, int row, unsigned char *data_buf,
154171
155172 /* Now decompress the row */
156173 if (fcb -> cellhd .compressed > 0 ) {
174+ if (readamount == 0 ) {
175+ G_free (cmp2 );
176+ G_fatal_error (_ ("Error reading raster data for row %d of <%s>" ),
177+ row , fcb -> name );
178+ }
179+
157180 /* one byte is nbyte count */
158181 n = * nbytes = * cmp ++ ;
159182 readamount -- ;
@@ -167,9 +190,13 @@ static void read_data_compressed(int fd, int row, unsigned char *data_buf,
167190 if (fcb -> cellhd .compressed == 1 )
168191 rle_decompress (data_buf , cmp , n , readamount );
169192 else {
170- if ((n = G_expand (cmp , readamount , data_buf , bufsize ,
193+ if (readamount > INT_MAX || bufsize > INT_MAX )
194+ G_fatal_error (_ ("Compressed raster row for <%s> is too large" ),
195+ fcb -> name );
196+
197+ if ((n = G_expand (cmp , (int )readamount , data_buf , (int )bufsize ,
171198 fcb -> cellhd .compressed )) < 0 ||
172- (unsigned int )n != bufsize ) {
199+ (size_t )n != bufsize ) {
173200 G_fatal_error (
174201 _ ("Error uncompressing raster data for row %d of <%s>" ),
175202 row , fcb -> name );
@@ -612,7 +639,7 @@ static void get_map_row(int fd, void *rast, int row, RASTER_MAP_TYPE data_type,
612639 int null_is_zero , int with_mask )
613640{
614641 struct fileinfo * fcb = & R__ .fileinfo [fd ];
615- int size = Rast_cell_size (data_type );
642+ size_t size = Rast_cell_size (data_type );
616643 CELL * temp_buf = NULL ;
617644 void * buf ;
618645 int type ;
@@ -844,16 +871,15 @@ static int read_null_bits_compressed(int null_fd, unsigned char *flags, int row,
844871 off_t t2 = fcb -> null_row_ptr [row + 1 ];
845872 size_t readamount = t2 - t1 ;
846873 unsigned char * compressed_buf ;
847- int res ;
874+ ssize_t res ;
848875
849876 if (lseek (null_fd , t1 , SEEK_SET ) == -1 )
850877 G_fatal_error (
851878 _ ("Error seeking compressed null data for row %d of <%s>" ), row ,
852879 fcb -> name );
853880
854881 if (readamount == size ) {
855- if ((res = read (null_fd , flags , size )) < 0 ||
856- (unsigned int )res != size ) {
882+ if ((res = read (null_fd , flags , size )) < 0 || (size_t )res != size ) {
857883 G_fatal_error (
858884 _ ("Error reading compressed null data for row %d of <%s>" ), row ,
859885 fcb -> name );
@@ -864,15 +890,19 @@ static int read_null_bits_compressed(int null_fd, unsigned char *flags, int row,
864890 compressed_buf = G_malloc (readamount );
865891
866892 if ((res = read (null_fd , compressed_buf , readamount )) < 0 ||
867- (unsigned int )res != readamount ) {
893+ (size_t )res != readamount ) {
868894 G_free (compressed_buf );
869895 G_fatal_error (
870896 _ ("Error reading compressed null data for row %d of <%s>" ), row ,
871897 fcb -> name );
872898 }
873899
874900 /* null bits file compressed with LZ4, see lib/gis/compress.h */
875- if (G_lz4_expand (compressed_buf , readamount , flags , size ) < 1 ) {
901+ if (readamount > INT_MAX || size > INT_MAX )
902+ G_fatal_error (_ ("Compressed null data for row %d of <%s> is too large" ),
903+ row , fcb -> name );
904+
905+ if (G_lz4_expand (compressed_buf , (int )readamount , flags , (int )size ) < 1 ) {
876906 G_fatal_error (_ ("Error uncompressing null data for row %d of <%s>" ),
877907 row , fcb -> name );
878908 }
0 commit comments