SplashDecodeGif() uses gif->SBackGroundColor as an index into colorMap->Colors 
when handling GIF_DISPOSE_BACKGND.

The background colour index is read from the GIF Logical Screen Descriptor and 
may contain a value from 0 to 255. The value is not validated against 
colorMap->ColorCount before indexing the colour table. A malformed GIF with a 
small colour table and an out-of-range SBackGroundColor can therefore cause an 
out-of-bounds heap read.

For example, a GIF with a colour table containing two entries and 
SBackGroundColor = 255 causes colorMap->Colors[255] to be accessed. The 
resulting colour value is subsequently used to fill the disposed frame 
background, exposing adjacent heap contents in the rendered splash image.

Add a bounds check ensuring SBackGroundColor is within ColorCount before 
indexing the colour table.

---------
- [x] I confirm that I make this contribution in accordance with the [OpenJDK 
Interim AI Policy](https://openjdk.org/legal/ai).

-------------

Commit messages:
 - 8393264: SplashDecodeGif may read past colour table

Changes: https://git.openjdk.org/jdk/pull/33145/files
  Webrev: https://webrevs.openjdk.org/?repo=jdk&pr=33145&range=00
  Issue: https://bugs.openjdk.org/browse/JDK-8393264
  Stats: 2 lines in 1 file changed: 1 ins; 0 del; 1 mod
  Patch: https://git.openjdk.org/jdk/pull/33145.diff
  Fetch: git fetch https://git.openjdk.org/jdk.git pull/33145/head:pull/33145

PR: https://git.openjdk.org/jdk/pull/33145

Reply via email to