#47359 [Opn->Ana]: XSS: incorrect mime type for bmp in getimagesize/image_type_to_mime_type()
| From: | scottmac@php.net | Date: | Wed, 11 Feb 2009 12:44:20 +0000 |
| Subject: | #47359 [Opn->Ana]: XSS: incorrect mime type for bmp in getimagesize/image_type_to_mime_type() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-133717@lists.php.net to get a copy of this message | ||
ID: 47359
Updated by: scottmac@php.net
Reported By: hsudhof at gmail dot com
-Status: Open
+Status: Analyzed
Bug Type: GetImageSize related
Operating System: Irrelevant
PHP Version: 5.2.9RC1
New Comment:
This looks like a bug in the IE mime type sniffing rather than a
specific XSS.
If I make the mime type image/bm or image/bmps or image/ms-bmp or any
of the half dozen that are listed they work correctly.
There is no official IANA mime type for bmp listed on the page so I'll
investigate this some more.
Previous Comments:
------------------------------------------------------------------------
[2009-02-11 11:53:26] hsudhof at gmail dot com
Description:
------------
For BMP images, image.c contains the mime type "image/bmp".
That mime type does not exist; the proper mime for bmp images is
"image/x-ms-bmp".
http://www.iana.org/assignments/media-types/image/
This is a problem, as this opens a XSS vulnerability for users with IE
< 8.
The reproduction code shows XSS, when the page is viewed with IE
versions earlier than IE8 Beta2.
Reproduce code:
---------------
<?php
$image =
'Qk1eAAAAAAAAAD4AAAAoAAAABwAAAAgAAAABAAEAAAAAACAAAAB0EgAAdDxzY3JpcHQ+YWxlcnQoJ1hTUyBkdWUgdG8gd3JvbmcgaGVhZGVyJyk7PC9zY3JpcHQ+AA==';
$file = base64_decode($image);
file_put_contents('test.bmp', $file);
$image_data = getimagesize('test.bmp');
header("Content-type: {$image_data['mime']}");
// echo "Expected: 'image/x-ms-bmp' ; actual :
'{$image_data['mime']}'";
header('Content-disposition: inline; filename="test.bmp"');
readfile('test.bmp');
// unlink('test.bmp');
Expected result:
----------------
Header: "image/x-ms-bmp"
Actual result:
--------------
Header : "image/bmp"; that causes a javascript popup when visiting with
IE6 and IE7.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=47359&edit=1