mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-09 02:43:09 -04:00
ReadJpeg() stored the JPEG header's width and height in the Image before calling WriteBuffer(). WriteBuffer() reallocates only when the requested size differs from the current one, so it saw no change and kept the existing buffer and linesize, and the scanline loop then decoded every row of a larger file past its end. A File monitor re-reads its source into a monitor-sized image on every capture, so whoever can write that file could overflow zmc's heap. Stored event JPEGs read by zms take the same path. Leave width and height to WriteBuffer(), as DecodeJpeg() already does. FileCamera::Capture() also now refuses a file whose dimensions do not match the monitor, since everything downstream is sized for the monitor. Add a Catch2 case that reads a 256x192 JPEG into a 64x48 image. It segfaulted before this change and passes after. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>