1 Description: Filename buffer overflow fix
2 This patch fixes a security hole by a bad buffer size handling.
3 Author: Roland Stigge <stigge@antcom.de>
4 Bug-Debian: http://bugs.debian.org/645118
6 --- a/src/libjasper/include/jasper/jas_stream.h
7 +++ b/src/libjasper/include/jasper/jas_stream.h
9 #include <jasper/jas_config.h>
13 #if defined(JAS_HAVE_FCNTL_H)
16 @@ -99,6 +100,12 @@ extern "C" {
21 +#define JAS_PATH_MAX PATH_MAX
23 +#define JAS_PATH_MAX 4096
29 @@ -251,7 +258,7 @@ typedef struct {
33 - char pathname[L_tmpnam + 1];
34 + char pathname[JAS_PATH_MAX + 1];
35 } jas_stream_fileobj_t;
37 #define JAS_STREAM_FILEOBJ_DELONCLOSE 0x01