Commit Graph

1009 Commits

Author SHA1 Message Date
9f7abaea3a Fix depth sanity test in PixelFormat 2020-09-21 12:47:22 +03:00
1224cbdc21 Handle empty Tight gradient rects
We always assumed there would be one pixel per row so a rect with
a zero width would result in us writing to unknown memory.

This could theoretically be used by a malicious server to inject
code in to the viewer process.

Issue found by Pavel Cheremushkin from Kaspersky Lab.
2020-09-21 12:46:27 +03:00
6a3f711878 Add write protection to OffsetPixelBuffer
No one should every try to write to this buffer. Enforce that by
throwing an exception if any one tries to get a writeable pointer
to the data.
2020-09-21 12:45:51 +03:00
3282836baf Make ZlibInStream more robust against failures
Move the checks around to avoid missing cases where we might access
memory that is no longer valid. Also avoid touching the underlying
stream implicitly (e.g. via the destructor) as it might also no
longer be valid.

A malicious server could theoretically use this for remote code
execution in the client.

Issue found by Pavel Cheremushkin from Kaspersky Lab
2020-09-21 12:40:12 +03:00
ac06594b12 Add .gitignore 2020-09-21 12:33:19 +03:00
5da407c11f Update README.md 2020-09-20 09:11:28 -04:00
313961153c Update install.sh
Modified installer to use release on GitHub
2020-09-20 09:04:35 -04:00
408c005d3e Initial commit v0.9.0-beta 2020-09-20 12:16:44 +00:00
09a4460ddb Initial commit 2020-09-13 12:50:42 -04:00