22124
|
1 |
--- gimp-2.6.10.orig/plug-ins/common/sphere-designer.c 2011-08-16 11:48:50.451538000 +0530
|
|
2 |
+++ gimp-2.6.10/plug-ins/common/sphere-designer.c 2011-08-16 11:53:08.714956000 +0530
|
|
3 |
@@ -1992,6 +1992,7 @@ loadit (const gchar * fn)
|
|
4 |
gchar endbuf[21 * (G_ASCII_DTOSTR_BUF_SIZE + 1)];
|
|
5 |
gchar *end = endbuf;
|
|
6 |
gchar line[1024];
|
|
7 |
+ gchar fmt_str[16];
|
|
8 |
gint i;
|
|
9 |
texture *t;
|
|
10 |
gint majtype, type;
|
|
11 |
@@ -2016,6 +2017,8 @@ loadit (const gchar * fn)
|
|
12 |
|
|
13 |
s.com.numtexture = 0;
|
|
14 |
|
|
15 |
+ snprintf (fmt_str, sizeof (fmt_str), "%%d %%d %%%lds", sizeof (endbuf) - 1);
|
|
16 |
+
|
|
17 |
while (!feof (f))
|
|
18 |
{
|
|
19 |
|
|
20 |
@@ -2026,7 +2029,7 @@ loadit (const gchar * fn)
|
|
21 |
t = &s.com.texture[i];
|
|
22 |
setdefaults (t);
|
|
23 |
|
|
24 |
- if (sscanf (line, "%d %d %s", &t->majtype, &t->type, end) != 3)
|
|
25 |
+ if (sscanf (line, fmt_str, &t->majtype, &t->type, end) != 3)
|
|
26 |
t->color1.x = g_ascii_strtod (end, &end);
|
|
27 |
if (end && errno != ERANGE)
|
|
28 |
t->color1.y = g_ascii_strtod (end, &end);
|
|
29 |
--- gimp-2.6.10.orig/plug-ins/gfig/gfig-style.c 2011-08-16 11:48:42.938675000 +0530
|
|
30 |
+++ gimp-2.6.10/plug-ins/gfig/gfig-style.c 2011-08-16 11:57:17.625677000 +0530
|
|
31 |
@@ -165,6 +165,7 @@ gfig_read_parameter_gimp_rgb (gchar
|
|
32 |
gchar *ptr;
|
|
33 |
gchar *tmpstr;
|
|
34 |
gchar *endptr;
|
|
35 |
+ gchar fmt_str[32];
|
|
36 |
gchar colorstr_r[G_ASCII_DTOSTR_BUF_SIZE];
|
|
37 |
gchar colorstr_g[G_ASCII_DTOSTR_BUF_SIZE];
|
|
38 |
gchar colorstr_b[G_ASCII_DTOSTR_BUF_SIZE];
|
|
39 |
@@ -172,6 +173,8 @@ gfig_read_parameter_gimp_rgb (gchar
|
|
40 |
|
|
41 |
style_entry->r = style_entry->g = style_entry->b = style_entry->a = 0.;
|
|
42 |
|
|
43 |
+ snprintf (fmt_str, sizeof (fmt_str), "%%%lds %%%lds %%%lds %%%lds", sizeof (colorstr_r) - 1, sizeof (colorstr_g) - 1, sizeof (colorstr_b) - 1, sizeof (colorstr_a) - 1);
|
|
44 |
+
|
|
45 |
while (n < nitems)
|
|
46 |
{
|
|
47 |
ptr = strchr (text[n], ':');
|
|
48 |
@@ -181,7 +184,7 @@ gfig_read_parameter_gimp_rgb (gchar
|
|
49 |
ptr++;
|
|
50 |
if (!strcmp (tmpstr, name))
|
|
51 |
{
|
|
52 |
- sscanf (ptr, "%s %s %s %s", colorstr_r, colorstr_g, colorstr_b, colorstr_a);
|
|
53 |
+ sscanf (ptr, fmt_str, colorstr_r, colorstr_g, colorstr_b, colorstr_a);
|
|
54 |
style_entry->r = g_ascii_strtod (colorstr_r, &endptr);
|
|
55 |
style_entry->g = g_ascii_strtod (colorstr_g, &endptr);
|
|
56 |
style_entry->b = g_ascii_strtod (colorstr_b, &endptr);
|
|
57 |
--- gimp-2.6.10.orig/plug-ins/lighting/lighting-ui.c 2011-08-16 11:48:41.292829000 +0530
|
|
58 |
+++ gimp-2.6.10/plug-ins/lighting/lighting-ui.c 2011-08-16 12:14:35.185283000 +0530
|
|
59 |
@@ -1342,6 +1342,7 @@ load_preset_response (GtkFileChooser *ch
|
|
60 |
gchar buffer3[G_ASCII_DTOSTR_BUF_SIZE];
|
|
61 |
gchar type_label[21];
|
|
62 |
gchar *endptr;
|
|
63 |
+ gchar fmt_str[32];
|
|
64 |
|
|
65 |
if (response_id == GTK_RESPONSE_OK)
|
|
66 |
{
|
|
67 |
@@ -1381,23 +1382,27 @@ load_preset_response (GtkFileChooser *ch
|
|
68 |
return;
|
|
69 |
}
|
|
70 |
|
|
71 |
- fscanf (fp, " Position: %s %s %s", buffer1, buffer2, buffer3);
|
|
72 |
+ snprintf (fmt_str, sizeof (fmt_str), " Position: %%%lds %%%lds %%%lds", sizeof (buffer1) - 1, sizeof (buffer2) - 1, sizeof (buffer3) - 1);
|
|
73 |
+ fscanf (fp, fmt_str, buffer1, buffer2, buffer3);
|
|
74 |
source->position.x = g_ascii_strtod (buffer1, &endptr);
|
|
75 |
source->position.y = g_ascii_strtod (buffer2, &endptr);
|
|
76 |
source->position.z = g_ascii_strtod (buffer3, &endptr);
|
|
77 |
|
|
78 |
- fscanf (fp, " Direction: %s %s %s", buffer1, buffer2, buffer3);
|
|
79 |
+ snprintf (fmt_str, sizeof (fmt_str), " Direction: %%%lds %%%lds %%%lds", sizeof (buffer1) - 1, sizeof (buffer2) - 1, sizeof (buffer3) - 1);
|
|
80 |
+ fscanf (fp, fmt_str, buffer1, buffer2, buffer3);
|
|
81 |
source->direction.x = g_ascii_strtod (buffer1, &endptr);
|
|
82 |
source->direction.y = g_ascii_strtod (buffer2, &endptr);
|
|
83 |
source->direction.z = g_ascii_strtod (buffer3, &endptr);
|
|
84 |
|
|
85 |
- fscanf (fp, " Color: %s %s %s", buffer1, buffer2, buffer3);
|
|
86 |
+ snprintf (fmt_str, sizeof (fmt_str), " Color: %%%lds %%%lds %%%lds", sizeof (buffer1) - 1, sizeof (buffer2) - 1, sizeof (buffer3) - 1);
|
|
87 |
+ fscanf (fp, fmt_str, buffer1, buffer2, buffer3);
|
|
88 |
source->color.r = g_ascii_strtod (buffer1, &endptr);
|
|
89 |
source->color.g = g_ascii_strtod (buffer2, &endptr);
|
|
90 |
source->color.b = g_ascii_strtod (buffer3, &endptr);
|
|
91 |
source->color.a = 1.0;
|
|
92 |
|
|
93 |
- fscanf (fp, " Intensity: %s", buffer1);
|
|
94 |
+ snprintf (fmt_str, sizeof (fmt_str), " Intensity: %%%lds", sizeof (buffer1) - 1);
|
|
95 |
+ fscanf (fp, fmt_str, buffer1);
|
|
96 |
source->intensity = g_ascii_strtod (buffer1, &endptr);
|
|
97 |
|
|
98 |
}
|
|
99 |
--- gimp-2.6.10.orig/plug-ins/common/file-psp.c 2011-08-16 11:48:49.945737000 +0530
|
|
100 |
+++ gimp-2.6.10/plug-ins/common/file-psp.c 2011-08-16 12:04:16.278205000 +0530
|
|
101 |
@@ -1246,13 +1246,14 @@ read_channel_data (FILE *f,
|
|
102 |
fread (buf, runcount, 1, f);
|
|
103 |
if (bytespp == 1)
|
|
104 |
{
|
|
105 |
+ runcount = MIN (runcount, endq - q);
|
|
106 |
memmove (q, buf, runcount);
|
|
107 |
q += runcount;
|
|
108 |
}
|
|
109 |
else
|
|
110 |
{
|
|
111 |
p = buf;
|
|
112 |
- for (i = 0; i < runcount; i++)
|
|
113 |
+ for (i = 0; i < runcount && q < endq; i++)
|
|
114 |
{
|
|
115 |
*q = *p++;
|
|
116 |
q += bytespp;
|