From f41da8f8e0f6f41ca522279274da1f2441828eda Mon Sep 17 00:00:00 2001 From: Even Rouault Date: Sun, 24 Mar 2019 17:11:55 +0100 Subject: vandg inverse: avoid division by zero Fixes https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13894 Credit to OSS Fuzz --- src/projections/vandg.cpp | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) (limited to 'src') diff --git a/src/projections/vandg.cpp b/src/projections/vandg.cpp index 89620356..c669f8fa 100644 --- a/src/projections/vandg.cpp +++ b/src/projections/vandg.cpp @@ -80,7 +80,14 @@ static PJ_LP s_inverse (PJ_XY xy, PJ *P) { /* Spheroidal, inverse */ al = c1 / c3 - THIRD * c2 * c2; m = 2. * sqrt(-THIRD * al); d = C2_27 * c2 * c2 * c2 + (c0 * c0 - THIRD * c2 * c1) / c3; - if (((t = fabs(d = 3. * d / (al * m))) - TOL) <= 1.) { + const double al_mul_m = al * m; + if( al_mul_m == 0 ) { + proj_errno_set(P, PJD_ERR_TOLERANCE_CONDITION); + return proj_coord_error().lp; + } + d = 3. * d /al_mul_m; + t = fabs(d); + if ((t - TOL) <= 1.) { d = t > 1. ? (d > 0. ? 0. : M_PI) : acos(d); lp.phi = M_PI * (m * cos(d * THIRD + PI4_3) - THIRD * c2); if (xy.y < 0.) lp.phi = -lp.phi; -- cgit v1.2.3