From b55d270161be73680767eecbeea55c500bf04c32 Mon Sep 17 00:00:00 2001 From: Sam Lantinga Date: Sun, 18 Jul 2010 10:08:06 -0700 Subject: [PATCH] Fixed bug 936 Make sure that eip doesn't overflow the copy buffer beforehand. :) --HG-- branch : SDL-1.2 --- src/video/SDL_stretch.c | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/src/video/SDL_stretch.c b/src/video/SDL_stretch.c index e16fd3fea..ac1ea24ea 100644 --- a/src/video/SDL_stretch.c +++ b/src/video/SDL_stretch.c @@ -78,7 +78,7 @@ static int generate_rowbytes(int src_w, int dst_w, int bpp) int i; int pos, inc; - unsigned char *eip; + unsigned char *eip, *end; unsigned char load, store; /* See if we need to regenerate the copy buffer */ @@ -115,7 +115,8 @@ static int generate_rowbytes(int src_w, int dst_w, int bpp) pos = 0x10000; inc = (src_w << 16) / dst_w; eip = copy_row; - for ( i=0; i= 0x10000L ) { if ( bpp == 2 ) { *eip++ = PREFIX16; @@ -132,8 +133,8 @@ static int generate_rowbytes(int src_w, int dst_w, int bpp) *eip++ = RETURN; /* Verify that we didn't overflow (too late!!!) */ - if ( eip > (copy_row+sizeof(copy_row)) ) { - SDL_SetError("Copy buffer overflow"); + if ( i < dst_w ) { + SDL_SetError("Copy buffer too small"); return(-1); } #ifdef HAVE_MPROTECT