Skip to content

Crop decompression - #2410

Merged
wiredfool merged 3 commits into
python-pillow:masterfrom
wiredfool:crop_decompression
Jun 21, 2017
Merged

wiredfool merged 3 commits into
python-pillow:masterfrom
wiredfool:crop_decompression

Conversation

@wiredfool

@wiredfool wiredfool commented Feb 17, 2017 •

Copy link
Copy Markdown
Member

Fixes #2402 .

Changes proposed in this pull request:

  • Add decompression bomb check for image.crop, since it can enlarge images.
  • Refactor out checks to _crop, so that we can apply them to any core image object.
  • Gif disposal is where the bug in out of memory when processing this GIF #2402 was, it was requesting a 1GP dispose_extents.

Still need to:
- [ ] Generate a gif with extra large extents

@homm

homm commented May 8, 2017

Copy link
Copy Markdown
Member

Consider making decompression bombs an error at some level

+1

@wiredfool
wiredfool force-pushed the crop_decompression branch from c0910ff to cbddaca Compare May 13, 2017 15:45
@wiredfool wiredfool added this to the 4.2.0 milestone Jun 13, 2017
@wiredfool

Copy link
Copy Markdown
Member Author

Since we've done this, there's been a change in the GIF code where the extent changes raise a ValueError, instead of triggering the decompression bomb here. Test is now on the https://github.com/wiredfool/Pillow/tree/dispose_extents_test branch. I've removed it here, rebased on master, and I'm going to merge this pending tests passing.

wiredfool added a commit to wiredfool/Pillow that referenced this pull request Jun 21, 2017
wiredfool added a commit to wiredfool/Pillow that referenced this pull request Jun 21, 2017
@wiredfool
wiredfool merged commit a4dafe7 into python-pillow:master Jun 21, 2017
wiredfool added a commit to wiredfool/Pillow that referenced this pull request Jun 21, 2017
@wiredfool
wiredfool deleted the crop_decompression branch October 2, 2017 13:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants