diff options
| author | Even Rouault <even.rouault@spatialys.com> | 2019-02-03 16:07:10 +0100 |
|---|---|---|
| committer | Even Rouault <even.rouault@spatialys.com> | 2019-02-03 16:07:10 +0100 |
| commit | 4abfe10ab7a64552db242aa240bbcf2f92598604 (patch) | |
| tree | 670f38370dae8af534aee200460a2ddf72c97839 /src/init.cpp | |
| parent | e121dc35abafd9a2eda01b05aa5fa13b13e6196e (diff) | |
| download | PROJ-4abfe10ab7a64552db242aa240bbcf2f92598604.tar.gz PROJ-4abfe10ab7a64552db242aa240bbcf2f92598604.zip | |
init(): repair to_meter=num/denom that was broken in the general case in PROJ 5; repair vto_meter=num/denom that was broken, and avoid division by zero, which fixes https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=12869. Credit to OSS Fuzz
Diffstat (limited to 'src/init.cpp')
| -rw-r--r-- | src/init.cpp | 35 |
1 files changed, 20 insertions, 15 deletions
diff --git a/src/init.cpp b/src/init.cpp index 482e398d..2961bcca 100644 --- a/src/init.cpp +++ b/src/init.cpp @@ -764,20 +764,18 @@ pj_init_ctx_with_allow_init_epsg(projCtx ctx, int argc, char **argv, int allow_i s = units[i].to_meter; } if (s || (s = pj_param(ctx, start, "sto_meter").s)) { - double factor; - int ratio = 0; - - /* ratio number? */ - if (strlen (s) > 1 && s[0] == '1' && s[1]=='/') { - ratio = 1; - s += 2; + char* end_ptr = const_cast<char*>(s); + PIN->to_meter = pj_strtod(s, &end_ptr); + s = end_ptr; + if (*s == '/') { /* ratio number */ + ++s; + double denom = pj_strtod(s, nullptr); + if (denom == 0.0) + return pj_default_destructor (PIN, PJD_ERR_UNIT_FACTOR_LESS_THAN_0); + PIN->to_meter /= denom; } - - factor = pj_strtod(s, nullptr); - if ((factor <= 0.0) || (1/factor==0)) + if (PIN->to_meter <= 0.0) return pj_default_destructor (PIN, PJD_ERR_UNIT_FACTOR_LESS_THAN_0); - - PIN->to_meter = ratio? 1 / factor: factor; PIN->fr_meter = 1 / PIN->to_meter; } else @@ -792,9 +790,16 @@ pj_init_ctx_with_allow_init_epsg(projCtx ctx, int argc, char **argv, int allow_i s = units[i].to_meter; } if (s || (s = pj_param(ctx, start, "svto_meter").s)) { - PIN->vto_meter = pj_strtod(s, nullptr); - if (*s == '/') /* ratio number */ - PIN->vto_meter /= pj_strtod(++s, nullptr); + char* end_ptr = const_cast<char*>(s); + PIN->vto_meter = pj_strtod(s, &end_ptr); + s = end_ptr; + if (*s == '/') { /* ratio number */ + ++s; + double denom = pj_strtod(s, nullptr); + if (denom == 0.0) + return pj_default_destructor (PIN, PJD_ERR_UNIT_FACTOR_LESS_THAN_0); + PIN->vto_meter /= denom; + } if (PIN->vto_meter <= 0.0) return pj_default_destructor (PIN, PJD_ERR_UNIT_FACTOR_LESS_THAN_0); PIN->vfr_meter = 1. / PIN->vto_meter; |
