From: Mattias Bengtsson Date: Tue, 23 Oct 2007 01:58:30 +0000 (+0000) Subject: -MFB, Be paranoid and dont allow multiplication with zero X-Git-Tag: RELEASE_1_3_1~819 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=b6e317e25cdf304b4702709c1c3b60043116daeb;p=php -MFB, Be paranoid and dont allow multiplication with zero --- diff --git a/ext/gd/libgd/gd_security.c b/ext/gd/libgd/gd_security.c index a5fea34c14..897c302539 100644 --- a/ext/gd/libgd/gd_security.c +++ b/ext/gd/libgd/gd_security.c @@ -19,12 +19,10 @@ int overflow2(int a, int b) { - if(a < 0 || b < 0) { - php_gd_error("gd warning: one parameter to a memory allocation multiplication is negative, failing operation gracefully\n"); + if(a <= 0 || b <= 0) { + php_gd_error("gd warning: one parameter to a memory allocation multiplication is negative or zero, failing operation gracefully\n"); return 1; } - if(b == 0) - return 0; if(a > INT_MAX / b) { php_gd_error("gd warning: product of memory allocation multiplication would exceed INT_MAX, failing operation gracefully\n"); return 1;