tiff: don't panic when decoding too-large image on 32-bit platforms

Includes a new internal/safemath package as a place to put an
overflow-checking Mul3 function stolen from std's image package,
since that seems like something we can use elsewhere in this repo.

This is not a security fix: Inputs whose natural size is too large
to fit in memory are not within our threat model.

Change-Id: I9b29109ac816e8b8eec18961eadd05696a6a6964
Reviewed-on: https://go-review.googlesource.com/c/image/+/787500
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Neal Patel <nealpatel@google.com>
Reviewed-by: Neal Patel <neal@golang.org>
Auto-Submit: Damien Neil <dneil@google.com>
3 files changed
tree: 757743a7607f3f1fcaf5e4d3aea5971d70ed1f72
  1. bmp/
  2. ccitt/
  3. cmd/
  4. colornames/
  5. draw/
  6. example/
  7. font/
  8. internal/
  9. math/
  10. riff/
  11. testdata/
  12. tiff/
  13. vector/
  14. vp8/
  15. vp8l/
  16. webp/
  17. .gitattributes
  18. .gitignore
  19. codereview.cfg
  20. CONTRIBUTING.md
  21. go.mod
  22. go.sum
  23. LICENSE
  24. PATENTS
  25. README.md
README.md

Go Images

Go Reference

This repository holds supplementary Go image packages.

Security Considerations

The packages in this repository have the same security model as the standard library image package. Specifically, when operating on arbitrary images, DecodeConfig should be called before Decode, so that the program can decide whether the image, as defined in the returned header, can be safely decoded with the available resources. A call to Decode which produces an extremely large image, as defined in the header returned by DecodeConfig, is not considered a security issue, regardless of whether the image is itself malformed or not.

Report Issues / Send Patches

This repository uses Gerrit for code changes. To learn how to submit changes to this repository, see https://go.dev/doc/contribute.

The git repository is https://go.googlesource.com/image.

The main issue tracker for the image repository is located at https://go.dev/issues. Prefix your issue with “x/image:” in the subject line, so it is easy to find.