From 0e51a9aca61dfc2cc44bf19a6ba23d423d7f204c Mon Sep 17 00:00:00 2001 From: Jay Berkenbilt Date: Wed, 28 Aug 2019 22:48:55 -0400 Subject: Don't encrypt trailer, fixes fuzz issue 15983 Ordinarily the trailer doesn't contain any strings, so this is usually a non-issue, but if the trailer contains strings, linearizing and encrypting with object streams would include encrypted strings in the trailer, which would blow out the padding because encrypted strings are longer than their cleartext counterparts. --- libqpdf/QPDFWriter.cc | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) (limited to 'libqpdf/QPDFWriter.cc') diff --git a/libqpdf/QPDFWriter.cc b/libqpdf/QPDFWriter.cc index f5fa2bc9..116d493f 100644 --- a/libqpdf/QPDFWriter.cc +++ b/libqpdf/QPDFWriter.cc @@ -1341,7 +1341,11 @@ QPDFWriter::writeTrailer(trailer_e which, int size, bool xref_stream, qpdf_offset_t prev, int linearization_pass) { QPDFObjectHandle trailer = getTrimmedTrailer(); - if (! xref_stream) + if (xref_stream) + { + this->m->cur_data_key.clear(); + } + else { writeString("trailer <<"); } @@ -3320,7 +3324,10 @@ QPDFWriter::writeLinearized() if (this->m->pipeline->getCount() != first_xref_end) { throw std::logic_error( - "insufficient padding for first pass xref stream"); + "insufficient padding for first pass xref stream; " + "first_xref_end=" + + QUtil::int_to_string(first_xref_end) + + "; endpos=" + QUtil::int_to_string(endpos)); } } writeString("\n"); -- cgit v1.2.3-54-g00ecf