T09 · Insecure Skill Coding Practices
- Location
scripts/cropper.py:31- Finding
Unvalidated Crop Height Causes Infinite Loop and Resource Exhaustion
- Content
View full analysis
= image_height: break return crops ``` The command-line interface accepts any integer for the crop height: ```python parser.add_argument('--height', type=int, default=DEFAULT_HEIGHT, help=f'目标高度(默认:{DEFAULT_HEIGHT}px,4:3 比例)') ``` The GUI similarly passes the user-controlled height directly into `process_image()`: ```python height = self.height_var.get() count = process_image( input_path=self.input_path, output_dir=str(self.output_dir), start_y=start_y, width=width, height=height, remove_logo=remove_logo, logo_height=logo_height, output_format=output_format ) ``` ### Technical Analysis The crop calculation assumes that `height` is a positive integer, but neither the command-line interface, GUI, `process_image()`, nor `calculate_crops()` enforces this invariant. When `height` is zero, the following assignment does not advance the loop: ```python y_end = min(current_y + 0, image_height) current_y = y_end ``` Consequently, `current_y` remains unchanged while the same tuple is repeatedly appended to `crops`. The loop continues until the process is terminated or available memory is exhausted. When `height` is negative, `y_end` and `current_y` move backward on every iteration. The loop condition remains true, and the list continues growing without a termina ...[truncated 1520 chars]- Remediation
View remediation
