fix: Consume chunk body in APNG push-mode discard paths
Restructure the trailing-fdAT path in the APNG push reader to check
PNG_HAVE_fcTLbefore callingpng_ensure_sequence_number, in order to ensure that an early return from insufficient buffer data cannot sit between the sequence read and the body consumption.Three inter-frame discard paths in
png_push_read_chunkused to clear the chunk-header flag without first consuming the chunk body and the CRC field. On a subsequent call topng_process_data, the unconsumed chunk bytes were reinterpreted as a fresh chunk header, which allowed attacker-controlled data inside an ignored chunk to be smuggled into the frame-data path.Reported-by: 신승민 guncraft2000@naver.com
版权所有:中国计算机学会技术支持:开源发展技术委员会
京ICP备13000930号-9
京公网安备 11010802032778号
README for libpng version 1.8.0.git
See the note about version numbers near the top of
png.h. SeeINSTALLfor instructions on how to install libpng.Libpng comes in several distribution formats. Get
libpng-*.tar.gzorlibpng-*.tar.xzif you want UNIX-style line endings in the text files, orlpng*.7zorlpng*.zipif you want DOS-style line endings.For a detailed description on using libpng, read
libpng-manual.txt. For examples of libpng in a program, seeexample.candpngtest.c. For usage information and restrictions (what little they are) on libpng, seepng.h. For a description on using zlib (the compression library used by libpng) and zlib’s restrictions, seezlib.h.You should use zlib 1.0.4 or later to run this, but it may work with versions as old as zlib 0.95. Even so, there are bugs in older zlib versions which can cause the output of invalid compression streams for some images.
You should also note that zlib is a compression library that is useful for more things than just PNG files. You can use zlib as a drop-in replacement for
fread()andfwrite(), if you are so inclined.zlib should be available at the same place that libpng is, or at https://zlib.net.
You may also want a copy of the PNG specification. It is available as an RFC, a W3C Recommendation, and an ISO/IEC Standard. You can find these at http://www.libpng.org/pub/png/pngdocs.html.
This code is currently being archived at https://libpng.sourceforge.io in the download area, and at http://libpng.download/src.
This release, based in a large way on Glenn’s, Guy’s and Andreas’ earlier work, was created and will be supported by myself and the PNG development group.
Send comments, corrections and commendations to
png-mng-implementatlists.sourceforge.net. (Subscription is required; visit https://lists.sourceforge.net/lists/listinfo/png-mng-implement to subscribe.)Send general questions about the PNG specification to
png-mng-miscatlists.sourceforge.net. (Subscription is required; visit https://lists.sourceforge.net/lists/listinfo/png-mng-misc to subscribe.)Historical notes
The libpng library has been in extensive use and testing since mid-1995. Version 0.89, published a year later, was the first official release. By late 1997, it had finally gotten to the stage where there hadn’t been significant changes to the API in some time, and people have a bad feeling about libraries with versions below 1.0. Version 1.0.0 was released in March 1998.
Note that some of the changes to the
png_infostructure render this version of the library binary incompatible with libpng-0.89 or earlier versions if you are using a shared library. The type of thefillerparameter forpng_set_filler()has changed frompng_bytetopng_uint_32, which will affect shared-library applications that use this function.To avoid problems with changes to the internals of the
info_struct, new APIs have been made available in 0.95 to avoid direct application access toinfo_ptr. These functions are thepng_set_<chunk>andpng_get_<chunk>functions. These functions should be used when accessing/storing theinfo_structdata, rather than manipulating it directly, to avoid such problems in the future.It is important to note that the APIs did not make current programs that access the info struct directly incompatible with the new library, through libpng-1.2.x. In libpng-1.4.x, which was meant to be a transitional release, members of the
png_structand theinfo_structcan still be accessed, but the compiler will issue a warning about deprecated usage. Since libpng-1.5.0, direct access to these structs is not allowed, and the definitions of the structs reside in privatepngstruct.handpnginfo.hheader files that are not accessible to applications. It is strongly suggested that new programs use the new APIs (as shown inexample.candpngtest.c), and older programs be converted to the new format, to facilitate upgrades in the future.The additions since 0.89 include the ability to read from a PNG stream which has had some (or all) of the signature bytes read by the calling application. This also allows the reading of embedded PNG streams that do not have the PNG file signature. As well, it is now possible to set the library action on the detection of chunk CRC errors. It is possible to set different actions based on whether the CRC error occurred in a critical or an ancillary chunk.
The additions since 0.90 include the ability to compile libpng as a Windows DLL, and new APIs for accessing data in the
info_struct. Experimental functions included the ability to set weighting and cost factors for row filter selection, direct reads of integers from buffers on big-endian processors that support misaligned data access, faster methods of doing alpha composition, and more accurate 16-to-8 bit color conversion. Some of these experimental functions, such as the weighted filter heuristics, have since been removed.Files included in this distribution
Good luck, and happy coding!