ReadTGA() sized both the image and its scratch buffer from the header's width, height and bpp without comparing them against the input stream, and never checked how much data the bulk reads actually returned. A 22 byte file declaring a 31232x16382 image at 24bpp therefore allocated 1.5 GB twice over, and, because a short read went undetected, LoadFile() returned true and handed back an image of the declared size that the file never contained. Reject dimensions whose claimed image size cannot fit the stream before allocating anything: uncompressed types must fit exactly, while the RLE variants are allowed up to 128:1 expansion, since each packet costs 1 + pixelSize input bytes and yields at most 128 * pixelSize output bytes. Also check LastRead() after the header read and after each of the three uncompressed bulk reads, so that a truncated file is reported as a failure instead of a success, as imagpcx.cpp has done since #26624; DecodeRLE() already validated its own reads. Fixes #26760. Closes #26761.
About
wxWidgets is a free and open source cross-platform C++ framework for writing advanced GUI applications using native controls.
wxWidgets allows you to write native-looking GUI applications for all the major desktop platforms and also helps with abstracting the differences in the non-GUI aspects between them. It is free for the use in both open source and commercial applications, comes with the full, easy to read and modify, source and extensive documentation and a collection of more than a hundred examples. You can learn more about wxWidgets at https://www.wxwidgets.org/ and read its documentation online at https://docs.wxwidgets.org/
Platforms
This version of wxWidgets supports the following primary platforms:
- Windows 7, 8, 10 and 11 (32/64 bit Intel and ARM64).
- Most Unix variants using the GTK+ toolkit (version 2.6 or newer or 3.x).
- macOS (10.10 or newer) using Cocoa under both amd64 and ARM platforms.
All C++11 compilers are supported including but not limited to:
- Microsoft Visual C++ 2015 or later (up to 2026).
- g++ 4.8 or later (up to 15), including MinGW/MinGW-64/TDM under Windows.
- Clang (up to 19/Xcode 16).
Please use 3.2 branch if you must use wxWidgets with a C++98 compiler or support Windows XP.
Licence
wxWidgets licence is a modified version of LGPL explicitly allowing not distributing the sources of an application using the library even in the case of static linking.
Building
For building the library, please see platform-specific documentation under
docs/<port> directory, e.g. here are the instructions for
wxGTK, wxMSW and
wxOSX.
If you're building the sources checked out from Git, and not from a released version, please see these additional Git-specific notes.
Contributing
Contributions to wxWidgets are always welcome, please don't hesitate to submit your patches or pull requests! If you are not sure how to do this, please check our guidelines explaining it.
Not all contributions have to be code, you can also help by improving documentation or translations, for which we have a separate page with more details.
Thank you in advance for your help in making wxWidgets better!
Further information
If you are looking for community support, you can get it from
- Mailing Lists
- Discussion Forums
- #wxwidgets IRC channel
- Stack Overflow
(tag your questions with
wxwidgets) - And you can report bugs at GitHub
Commercial support is also available.
Finally, keep in mind that wxWidgets is an open source project collaboratively developed by its users and your contributions to it are always welcome. Please check our guidelines if you'd like to do it.
Have fun!
The wxWidgets Team.
