From: Cristy Date: Tue, 10 Apr 2018 23:10:10 +0000 (-0400) Subject: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=7535 X-Git-Tag: 7.0.7-29~141 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=1d69ad385f5bac239b29e71d1c856eabd3ca3fb7;p=imagemagick https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=7535 --- diff --git a/MagickCore/draw.c b/MagickCore/draw.c index 54f173e19..ae8eece74 100644 --- a/MagickCore/draw.c +++ b/MagickCore/draw.c @@ -1531,7 +1531,7 @@ static MagickBooleanType DrawDashPolygon(const DrawInfo *draw_info, for (i=0; primitive_info[i].primitive != UndefinedPrimitive; i++) ; number_vertices=(size_t) i; dash_polygon=(PrimitiveInfo *) AcquireQuantumMemory((size_t) - (2UL*(number_vertices+6UL)+6UL),sizeof(*dash_polygon)); + (2UL*number_vertices+32UL),sizeof(*dash_polygon)); if (dash_polygon == (PrimitiveInfo *) NULL) return(MagickFalse); clone_info=CloneDrawInfo((ImageInfo *) NULL,draw_info);