The GitHub Actions job "Java CI with Gradle" on 
poi.git/hemf-bounds-check-before-narrowing has succeeded.
Run started by GitHub user pjfanning (triggered by pjfanning).

Head commit for run:
98c2625e06e99dd58b7962dc23b6cbbe2c4c40b0 / PJ Fanning 
<[email protected]>
Bounds check untrusted 32-bit counts before narrowing them to int

Several parsers read an unsigned 32-bit count or size field, narrow it with
Math.toIntExact, and only then range check it. For a field above
Integer.MAX_VALUE the narrowing throws ArithmeticException first, so the check
that follows never runs and the caller sees an unrelated exception instead of
the RecordFormatException the guards are written to produce.

Keep these values as longs until after the check. The IOUtils/ArrayUtil
checkers already take a long and already reject both negative and
over-Integer.MAX_VALUE lengths with a descriptive message.

Sites changed:

* HemfDraw.EmfPolyBezier / EmfPolygon - the spec says extra points MUST be
  ignored and the code caps the count at 16K, but the narrowing ran first, so
  an oversized count was rejected instead of clamped.
* HemfDraw.EmfPolyDraw - narrowing pre-empted HemfPicture.safelyAllocateCheck.
* HemfComment.EmfCommentDataBeginGroup / EmfCommentDataWMF - narrowing
  pre-empted IOUtils.safelyAllocate.
* hpsf Section.readDictionary - the oversize test sits outside the try/catch
  that records a corrupted dictionary, so the narrowing threw
  ArithmeticException out of the Section constructor rather than taking the
  corrupted-dictionary path.

Reported for the EMF records by a security researcher. The EMF paths are not
themselves an availability problem: HemfRecordIterator already wraps any
RuntimeException into RecordFormatException, and the allocation guards
themselves were added in #1104, #1107 and #1114. This corrects the ordering so
the guards report what they were meant to report.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>

Report URL: https://github.com/apache/poi/actions/runs/35726034112

With regards,
GitHub Actions via GitBox


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to